vendor:
BIG-IP
by:
Florent Daigniere
7,5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: BIG-IP
Affected Version From: 9.x
Affected Version To: 11.x
Patch Exists: YES
Related CWE: CVE-2012-1493
CPE: a:f5:big-ip
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-1455/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-1456/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-0625/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-0626/, https://www.rapid7.com/db/vulnerabilities/ssh-f5-cve-2012-1493/, https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2012-1493/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: BIG-IP platforms without SCCP
2012
F5 BIG-IP remote root authentication bypass Vulnerability
Vulnerable BIG-IP installations allow unauthenticated users to bypass authentication and login as the 'root' user on the device. The SSH private key corresponding to the following public key is public and present on all vulnerable appliances.
Mitigation:
BIG-IP version 11.1.0 build 1943.0 tested. The vendor reports that the following versions are patched: 9.4.8-HF5 and later, 10.2.4 and later, 11.0.0-HF2 and later, 11.1.0-HF3 and later