CVE-2019-6642

8.8HIGH

Key Information:

Vendor
F5
Vendor
CVE Published:
1 July 2019

Summary

In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, authenticated users with the ability to upload files (via scp, for example) can escalate their privileges to allow root shell access from within the TMOS Shell (tmsh) interface. The tmsh interface allows users to execute a secondary program via tools like sftp or scp.

Affected Version(s)

BIG-IP, BIG-IQ, iWorkflow, Enterprise Manager BIG-IP 15.0.0

BIG-IP, BIG-IQ, iWorkflow, Enterprise Manager 14.0.0-14.1.0.5

BIG-IP, BIG-IQ, iWorkflow, Enterprise Manager 13.0.0-13.1.1.5

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.