ID

VAR-200908-0116


CVE

CVE-2008-7032


TITLE

F5 BIG-IP of Web Management console cross-site request forgery vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2009-003103

DESCRIPTION

Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3 allows remote attackers to hijack the authentication of administrators for requests that create new administrators and execute shell commands, as demonstrated using tmui/Control/form. F5 BIG-IP is prone to a cross-site request-forgery vulnerability. Exploiting this issue may allow a remote attacker to execute arbitrary actions on an affected device. F5 BIG-IP 9.4.3 is vulnerable; other versions may also be affected. F5 BIG-IP is a load balancer. A remote attacker could hijack authentication of administrator requests

Trust: 2.07

sources: NVD: CVE-2008-7032 // JVNDB: JVNDB-2009-003103 // BID: 27720 // VULHUB: VHN-37157 // VULMON: CVE-2008-7032

AFFECTED PRODUCTS

vendor:f5model:big-ipscope:eqversion:9.4.3

Trust: 2.4

vendor:f5model:bigipscope:eqversion:9.4.3

Trust: 0.3

sources: BID: 27720 // JVNDB: JVNDB-2009-003103 // CNNVD: CNNVD-200908-345 // NVD: CVE-2008-7032

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2008-7032
value: MEDIUM

Trust: 1.0

NVD: CVE-2008-7032
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200908-345
value: MEDIUM

Trust: 0.6

VULHUB: VHN-37157
value: MEDIUM

Trust: 0.1

VULMON: CVE-2008-7032
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2008-7032
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-37157
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-37157 // VULMON: CVE-2008-7032 // JVNDB: JVNDB-2009-003103 // CNNVD: CNNVD-200908-345 // NVD: CVE-2008-7032

PROBLEMTYPE DATA

problemtype:CWE-352

Trust: 1.9

sources: VULHUB: VHN-37157 // JVNDB: JVNDB-2009-003103 // NVD: CVE-2008-7032

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200908-345

TYPE

cross-site request forgery

Trust: 0.6

sources: CNNVD: CNNVD-200908-345

CONFIGURATIONS

sources: JVNDB: JVNDB-2009-003103

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-37157 // VULMON: CVE-2008-7032

PATCH

title:Top Pageurl:http://www.f5.com/products/big-ip/

Trust: 0.8

sources: JVNDB: JVNDB-2009-003103

EXTERNAL IDS

db:NVDid:CVE-2008-7032

Trust: 2.9

db:BIDid:27720

Trust: 2.1

db:OSVDBid:50985

Trust: 1.8

db:JVNDBid:JVNDB-2009-003103

Trust: 0.8

db:CNNVDid:CNNVD-200908-345

Trust: 0.7

db:XFid:5

Trust: 0.6

db:XFid:40419

Trust: 0.6

db:BUGTRAQid:20080210 F5 BIG-IP WEB MANAGEMENT CONSOLE CSRF (WITH EXAMPLE)

Trust: 0.6

db:BUGTRAQid:20080210 F5 BIG-IP WEB MANAGEMENT CONSOLE CSRF

Trust: 0.6

db:EXPLOIT-DBid:31133

Trust: 0.2

db:SEEBUGid:SSVID-84485

Trust: 0.1

db:VULHUBid:VHN-37157

Trust: 0.1

db:VULMONid:CVE-2008-7032

Trust: 0.1

sources: VULHUB: VHN-37157 // VULMON: CVE-2008-7032 // BID: 27720 // JVNDB: JVNDB-2009-003103 // CNNVD: CNNVD-200908-345 // NVD: CVE-2008-7032

REFERENCES

url:http://www.securityfocus.com/bid/27720

Trust: 1.9

url:http://osvdb.org/50985

Trust: 1.8

url:http://www.securityfocus.com/archive/1/487862/100/200/threaded

Trust: 1.2

url:http://www.securityfocus.com/archive/1/487863/100/200/threaded

Trust: 1.2

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/40419

Trust: 1.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2008-7032

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2008-7032

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/40419

Trust: 0.6

url:http://www.securityfocus.com/archive/1/archive/1/487863/100/200/threaded

Trust: 0.6

url:http://www.securityfocus.com/archive/1/archive/1/487862/100/200/threaded

Trust: 0.6

url:http://www.f5.com/f5products/bigip/

Trust: 0.3

url:/archive/1/487863

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/352.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://www.exploit-db.com/exploits/31133/

Trust: 0.1

sources: VULHUB: VHN-37157 // VULMON: CVE-2008-7032 // BID: 27720 // JVNDB: JVNDB-2009-003103 // CNNVD: CNNVD-200908-345 // NVD: CVE-2008-7032

CREDITS

nnposter is credited with the discovery of this vulnerability.

Trust: 0.3

sources: BID: 27720

SOURCES

db:VULHUBid:VHN-37157
db:VULMONid:CVE-2008-7032
db:BIDid:27720
db:JVNDBid:JVNDB-2009-003103
db:CNNVDid:CNNVD-200908-345
db:NVDid:CVE-2008-7032

LAST UPDATE DATE

2024-11-23T20:12:37.786000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-37157date:2018-10-11T00:00:00
db:VULMONid:CVE-2008-7032date:2018-10-11T00:00:00
db:BIDid:27720date:2015-04-16T18:06:00
db:JVNDBid:JVNDB-2009-003103date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200908-345date:2009-08-25T00:00:00
db:NVDid:CVE-2008-7032date:2024-11-21T00:58:06.170

SOURCES RELEASE DATE

db:VULHUBid:VHN-37157date:2009-08-24T00:00:00
db:VULMONid:CVE-2008-7032date:2009-08-24T00:00:00
db:BIDid:27720date:2008-02-11T00:00:00
db:JVNDBid:JVNDB-2009-003103date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200908-345date:2009-08-24T00:00:00
db:NVDid:CVE-2008-7032date:2009-08-24T10:30:01.750