MEDIUM
On BIG-IP 12.1.0-12.1.4.1, undisclosed requests can cause iControl REST processes to crash
Published Jul 3, 2019
6.5
MEDIUMCVSS 3.1
EPSS 2.04%
Description
On BIG-IP 12.1.0-12.1.4.1, undisclosed requests can cause iControl REST processes to crash. The attack can only come from an authenticated user; all roles are capable of performing the attack. Unauthenticated users cannot perform this attack.
Affected products
-
- Version BIG-IP 12.1.0-12.1.4.1StatusaffectedConstraints-
- Version
OR
- ≥ 12.1.2 · ≤ 12.1.4
- ≥ 12.1.2 · ≤ 12.1.4
- ≥ 12.1.2 · ≤ 12.1.4
- ≥ 12.1.2 · ≤ 12.1.4
- ≥ 12.1.2 · ≤ 12.1.4
- ≥ 12.1.2 · ≤ 12.1.4
- ≥ 12.1.2 · ≤ 12.1.4
- ≥ 12.1.2 · ≤ 12.1.4
- ≥ 12.1.2 · ≤ 12.1.4
- ≥ 12.1.2 · ≤ 12.1.4
- ≥ 12.1.2 · ≤ 12.1.4
- ≥ 12.1.2 · ≤ 12.1.4
- ≥ 12.1.2 · ≤ 12.1.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (3)
- http://www.securityfocus.com/bid/109060 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://support.f5.com/csp/article/K22384173 x_refsource_CONFIRMVendor Advisory
- https://support.f5.com/csp/article/K22384173?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/109060 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://support.f5.com/csp/article/K22384173 | x_refsource_CONFIRMVendor Advisory | |
| https://support.f5.com/csp/article/K22384173?utm_source=f5support&%3Butm_medium=RSS | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner f5
Published Jul 3, 2019
Updated Aug 4, 2024
Reserved Jan 22, 2019
Link CVE-2019-6641
CISA Vulnrichment
Updated n/a