On versions 11.2.1
Published Dec 28, 2018
5.5
MEDIUMCVSS 3.0
EPSS 0.39%
Description
On versions 11.2.1. and greater, unrestricted Snapshot File Access allows BIG-IP system's user with any role, including Guest Role, to have access and download previously generated and available snapshot files on the BIG-IP configuration utility such as QKView and TCPDumps.
Affected products
-
- Version All versions 11.2.1+StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| F5 Networks, Inc. | n/a | n/a |
|
Configuration 1
- ≥ 11.2.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
Configuration 2
- ≥ 11.2.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
Configuration 3
- ≥ 11.2.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
Configuration 4
- ≥ 11.2.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
Configuration 5
- ≥ 11.2.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
Configuration 6
- ≥ 11.2.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
Configuration 7
- ≥ 11.2.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
Configuration 8
- ≥ 11.2.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
Configuration 9
- ≥ 11.2.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
Configuration 10
- ≥ 11.2.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
Configuration 11
- ≥ 11.2.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
Configuration 12
- ≥ 11.2.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
Configuration 13
- ≥ 11.2.1 · ≤ 11.6.3
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- http://www.securityfocus.com/bid/106380 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://support.f5.com/csp/article/K53620021 x_refsource_CONFIRMVendor Advisory
- https://support.f5.com/csp/article/K53620021?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/106380 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://support.f5.com/csp/article/K53620021 | x_refsource_CONFIRMVendor Advisory | |
| https://support.f5.com/csp/article/K53620021?utm_source=f5support&%3Butm_medium=RSS | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.