F5 BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5.9 and Enterprise Manager 3.1.1 may expose sensitive information and allow the system configuration to be modified when using non-default ConfigSync settings
Published Sep 20, 2019
9.1
CRITICALCVSS 3.1
EPSS 1.29%
Description
F5 BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5.9 and Enterprise Manager 3.1.1 may expose sensitive information and allow the system configuration to be modified when using non-default ConfigSync settings.
Affected products
-
Affected
- 11.5.1-11.5.9
- 11.6.0-11.6.4
- 12.1.0-12.1.4.1
- 13.0.0-13.1.1.5
- 14.0.0-14.0.0.5
- 14.1.0-14.1.0.6
- BIG-IP 15.0.0
- EM 3.1.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| F5 Networks | BIG-IP, Enterprise Manager | unknown | Affected
|
Configuration 1
- ≥ 11.5.2 · ≤ 11.5.9
- ≥ 11.6.1 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- 14.0.0
- 14.1.0
- 15.0.0
Configuration 2
- ≥ 11.5.2 · ≤ 11.5.9
- ≥ 11.6.1 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- 14.0.0
- 14.1.0
- 15.0.0
Configuration 3
- ≥ 11.5.2 · ≤ 11.5.9
- ≥ 11.6.1 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- 14.0.0
- 14.1.0
- 15.0.0
Configuration 4
- ≥ 11.5.2 · ≤ 11.5.9
- ≥ 11.6.1 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- 14.0.0
- 14.1.0
- 15.0.0
Configuration 5
- ≥ 11.5.2 · ≤ 11.5.9
- ≥ 11.6.1 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- 14.0.0
- 14.1.0
- 15.0.0
Configuration 6
- ≥ 11.5.2 · ≤ 11.5.9
- ≥ 11.6.1 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- 14.0.0
- 14.1.0
- 15.0.0
Configuration 7
- ≥ 11.5.2 · ≤ 11.5.9
- ≥ 11.6.1 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- 14.0.0
- 14.1.0
- 15.0.0
Configuration 8
- ≥ 11.5.2 · ≤ 11.5.9
- ≥ 11.6.1 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- 14.0.0
- 14.1.0
- 15.0.0
Configuration 9
- ≥ 11.5.2 · ≤ 11.5.9
- ≥ 11.6.1 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- 14.0.0
- 14.1.0
- 15.0.0
Configuration 10
- ≥ 11.5.2 · ≤ 11.5.9
- ≥ 11.6.1 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- 14.0.0
- 14.1.0
- 15.0.0
Configuration 11
- ≥ 11.5.2 · ≤ 11.5.9
- ≥ 11.6.1 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- 14.0.0
- 14.1.0
- 15.0.0
Configuration 12
- ≥ 11.5.2 · ≤ 11.5.9
- ≥ 11.6.1 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- 14.0.0
- 14.1.0
- 15.0.0
Configuration 13
- 3.1.1
Configuration 14
- ≥ 11.5.2 · ≤ 11.5.9
- ≥ 11.6.1 · ≤ 11.6.4
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- 14.0.0
- 14.1.0
- 15.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-16208 Advisory
- https://support.f5.com/csp/article/K05123525 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-16208 | Advisory | |
| https://support.f5.com/csp/article/K05123525 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data