CVE-2017-6165
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 11.6.1 HF1, and 12.0.0 through 12.1.2 on VIPRION platforms only, the script which synchronizes SafeNet External…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.93%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 11.6.1 HF1, and 12.0.0 through 12.1.2 on VIPRION platforms only, the script which synchronizes SafeNet External Network HSM configuration elements between blades in a clustered deployment will log the HSM partition password in cleartext to the "/var/log/ltm" log file.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.93% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- f5/big-ip access policy manager · f5/big-ip advanced firewall manager · f5/big-ip analytics · f5/big-ip application acceleration manager · f5/big-ip application security manager · f5/big-ip domain name system · f5/big-ip global traffic manager · f5/big-ip link controller · f5/big-ip local traffic manager · f5/big-ip policy enforcement manager · f5/big-ip websafe
- Source
- f5sirt@f5.com
References
- http://www.securityfocus.com/bid/101543Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039638Third Party Advisory, VDB Entry
- https://support.f5.com/csp/article/K74759095Vendor Advisory
- http://www.securityfocus.com/bid/101543Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039638Third Party Advisory, VDB Entry
- https://support.f5.com/csp/article/K74759095Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.