Security Flaw in BIG-IP and BIG-IQ Products from F5 Networks
CVE-2019-6651

5.3MEDIUM

Key Information:

Vendor
F5
Vendor
CVE Published:
25 September 2019

Summary

A security vulnerability exists in F5 Networks' BIG-IP and BIG-IQ products where the Configuration utility login page may not adequately secure against malicious requests. This could potentially allow an attacker to exploit the utility, increasing the risk of unauthorized access and impacting system integrity. It is crucial for users to implement recommended security practices to safeguard their environments.

Affected Version(s)

BIG-IP, BIG-IQ, iWorkflow, Enterprise Manager BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4, BIG-IQ 7.0.0, 6.0.0-6.1.0,5.2.0-5.4.0, iWorkflow 2.3.0, Enterprise Manager 3.1.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.