ID

VAR-201610-0128


CVE

CVE-2016-5700


TITLE

F5 BIG-IP Vulnerability to change system settings in system virtual server

Trust: 0.8

sources: JVNDB: JVNDB-2016-005087

DESCRIPTION

Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2, when configured with the HTTP Explicit Proxy functionality or SOCKS profile, allow remote attackers to modify the system configuration, read system files, and possibly execute arbitrary code via unspecified vectors. Supplementary information : CWE Vulnerability type by CWE-284: Improper Access Control ( Inappropriate access control ) Has been identified. http://cwe.mitre.org/data/definitions/284.htmlA third party may change system settings, read system files, and execute arbitrary code. Multiple F5 BIG-IP Products are prone to a remote command-execution vulnerability. An attacker can execute arbitrary system commands within the context of the affected application. F5 BIG-IP is an all-in-one network device integrated with network traffic management, application security management, load balancing and other functions from F5 Corporation of the United States. The following versions are affected: F5 BIG-IP System version 11.5.0, version 11.5.1 before HF11, version 11.5.2, version 11.5.3, version 11.5.4 before HF2, version 11.6.0 before HF8, HF1 Version 11.6.1 before, Version 12.0.0 before HF4, Version 12.1.0 before HF2

Trust: 1.98

sources: NVD: CVE-2016-5700 // JVNDB: JVNDB-2016-005087 // BID: 93325 // VULHUB: VHN-94519

AFFECTED PRODUCTS

vendor:f5model:big-ip websafescope:eqversion:11.6.1

Trust: 2.7

vendor:f5model:big-ip local traffic managerscope:eqversion:11.6.1

Trust: 2.4

vendor:f5model:big-ip link controllerscope:eqversion:11.6.1

Trust: 2.1

vendor:f5model:big-ip link controllerscope:eqversion:11.5.4

Trust: 1.9

vendor:f5model:big-ip access policy managerscope:eqversion:11.6.1

Trust: 1.8

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.6.1

Trust: 1.8

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.6.1

Trust: 1.8

vendor:f5model:big-ip application security managerscope:eqversion:11.6.1

Trust: 1.8

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.6.1

Trust: 1.8

vendor:f5model:big-ip link controllerscope:eqversion:11.6.0

Trust: 1.6

vendor:f5model:big-ip application security managerscope:eqversion:12.0.0

Trust: 1.6

vendor:f5model:big-ip application security managerscope:eqversion:11.5.4

Trust: 1.6

vendor:f5model:big-ip application security managerscope:eqversion:11.5.3

Trust: 1.6

vendor:f5model:big-ip application security managerscope:eqversion:11.6.0

Trust: 1.6

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.6.0

Trust: 1.6

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.3

Trust: 1.6

vendor:f5model:big-ip link controllerscope:eqversion:11.5.2

Trust: 1.3

vendor:f5model:big-ip link controllerscope:eqversion:11.5.1

Trust: 1.3

vendor:f5model:big-ip link controllerscope:eqversion:12.1.0

Trust: 1.3

vendor:f5model:big-ip application security managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.5.4

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:12.0.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip websafescope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.5.4

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:12.0.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip websafescope:eqversion:12.0.0

Trust: 1.0

vendor:f5model:big-ip websafescope:eqversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.4

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:12.0.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.5.4

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:12.0.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.5.4

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:12.0.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:12.0.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.5.0 to 11.5.1 hf10

Trust: 0.8

vendor:f5model:big-ip access policy managerscope:eqversion:11.5.2 to 11.5.4 hf1

Trust: 0.8

vendor:f5model:big-ip access policy managerscope:eqversion:11.6.0 to 11.6.0 hf7

Trust: 0.8

vendor:f5model:big-ip access policy managerscope:eqversion:12.0.0 to 12.0.0 hf3

Trust: 0.8

vendor:f5model:big-ip access policy managerscope:eqversion:12.1.0 to 12.1.0 hf1

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.5.0 to 11.5.1 hf10

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.5.2 to 11.5.4 hf1

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.6.0 to 11.6.0 hf7

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope:eqversion:12.0.0 to 12.0.0 hf3

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope:eqversion:12.1.0 to 12.1.0 hf1

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.5.0 to 11.5.1 hf10

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.5.2 to 11.5.4 hf1

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.6.0 to 11.6.0 hf7

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope:eqversion:12.0.0 to 12.0.0 hf3

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope:eqversion:12.1.0 to 12.1.0 hf1

Trust: 0.8

vendor:f5model:big-ip application security managerscope:eqversion:11.5.0 to 11.5.1 hf10

Trust: 0.8

vendor:f5model:big-ip application security managerscope:eqversion:11.5.2 to 11.5.4 hf1

Trust: 0.8

vendor:f5model:big-ip application security managerscope:eqversion:11.6.0 to 11.6.0 hf7

Trust: 0.8

vendor:f5model:big-ip application security managerscope:eqversion:12.0.0 to 12.0.0 hf3

Trust: 0.8

vendor:f5model:big-ip application security managerscope:eqversion:12.1.0 to 12.1.0 hf1

Trust: 0.8

vendor:f5model:big-ip link controllerscope:eqversion:11.5.0 to 11.5.1 hf10

Trust: 0.8

vendor:f5model:big-ip link controllerscope:eqversion:11.5.2 to 11.5.4 hf1

Trust: 0.8

vendor:f5model:big-ip link controllerscope:eqversion:11.6.0 to 11.6.0 hf7

Trust: 0.8

vendor:f5model:big-ip link controllerscope:eqversion:12.0.0 to 12.0.0 hf3

Trust: 0.8

vendor:f5model:big-ip link controllerscope:eqversion:12.1.0 to 12.1.0 hf1

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.0 to 11.5.1 hf10

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.2 to 11.5.4 hf1

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:eqversion:11.6.0 to 11.6.0 hf7

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:eqversion:12.0.0 to 12.0.0 hf3

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:eqversion:12.1.0 to 12.1.0 hf1

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.5.0 to 11.5.1 hf10

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.5.2 to 11.5.4 hf1

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.6.0 to 11.6.0 hf7

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope:eqversion:12.0.0 to 12.0.0 hf3

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope:eqversion:12.1.0 to 12.1.0 hf1

Trust: 0.8

vendor:f5model:big-ip websafescope:eqversion:11.6.0 to 11.6.0 hf7

Trust: 0.8

vendor:f5model:big-ip websafescope:eqversion:12.0.0 to 12.0.0 hf3

Trust: 0.8

vendor:f5model:big-ip websafescope:eqversion:12.1.0 to 12.1.0 hf1

Trust: 0.8

vendor:f5model:big-ip websafe hf1scope:eqversion:12.1

Trust: 0.3

vendor:f5model:big-ip websafescope:eqversion:12.1

Trust: 0.3

vendor:f5model:big-ip websafe hf3scope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip websafe hf2scope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip websafe hf1scope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip websafescope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip websafescope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip psmscope:eqversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip psmscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip pem hf1scope:eqversion:12.1

Trust: 0.3

vendor:f5model:big-ip pem hf3scope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip pem hf2scope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip pem hf6scope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip pem hf1scope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip pem hf10scope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:11.5

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:12.1.0

Trust: 0.3

vendor:f5model:big-ip pem hf1scope:eqversion:12.0.0

Trust: 0.3

vendor:f5model:big-ip pem hf5scope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip pem hf4scope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip ltm hf1scope:eqversion:12.1

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip ltm hf7scope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip ltm hf6scope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip ltm hf1scope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:11.5.2

Trust: 0.3

vendor:f5model:big-ip ltm hf10scope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:11.5

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:12.1.0

Trust: 0.3

vendor:f5model:big-ip ltm hf3scope:eqversion:12.0.0

Trust: 0.3

vendor:f5model:big-ip ltm hf2scope:eqversion:12.0.0

Trust: 0.3

vendor:f5model:big-ip ltm hf1scope:eqversion:12.0.0

Trust: 0.3

vendor:f5model:big-ip ltm hf5scope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip ltm hf4scope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip link controller hf1scope:eqversion:12.1

Trust: 0.3

vendor:f5model:big-ip link controller hf3scope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip link controller hf2scope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip link controller buildscope:eqversion:12.01.14.628

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip link controller hf6scope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip link controller hf4scope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip link controller hf1scope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip link controller hf10scope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:11.5

Trust: 0.3

vendor:f5model:big-ip link controller hf1scope:eqversion:12.0.0

Trust: 0.3

vendor:f5model:big-ip link controller hf5scope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:12.1.0

Trust: 0.3

vendor:f5model:big-ip asm hf1scope:eqversion:12.1

Trust: 0.3

vendor:f5model:big-ip asm buildscope:eqversion:12.01.14.628

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip asm hf7scope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip asm hf6scope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip asm hf1scope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.5.2

Trust: 0.3

vendor:f5model:big-ip asm hf10scope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.5

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:12.1.0

Trust: 0.3

vendor:f5model:big-ip asm hf3scope:eqversion:12.0.0

Trust: 0.3

vendor:f5model:big-ip asm hf2scope:eqversion:12.0.0

Trust: 0.3

vendor:f5model:big-ip asm hf1scope:eqversion:12.0.0

Trust: 0.3

vendor:f5model:big-ip asm hf5scope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip asm hf4scope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip apm hf1scope:eqversion:12.1

Trust: 0.3

vendor:f5model:big-ip apm hf3scope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip apm hf2scope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip apm buildscope:eqversion:12.01.14.628

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip apm hf7scope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip apm hf6scope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip apm hf5scope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip apm hf4scope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip apm hf3scope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip apm hf1scope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip apm hf1scope:eqversion:11.5.2

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.5.2

Trust: 0.3

vendor:f5model:big-ip apm hf10scope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:12.1.0

Trust: 0.3

vendor:f5model:big-ip apm hf1scope:eqversion:12.0.0

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.5.0

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:12.1.0

Trust: 0.3

vendor:f5model:big-ip afm hf1scope:eqversion:12.1

Trust: 0.3

vendor:f5model:big-ip afm buildscope:eqversion:12.01.14.628

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip afm hf7scope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip afm hf6scope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip afm buildscope:eqversion:11.66.204.442

Trust: 0.3

vendor:f5model:big-ip afm hf1scope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:11.5.2

Trust: 0.3

vendor:f5model:big-ip afm hf10scope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:11.5

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:12.1.0

Trust: 0.3

vendor:f5model:big-ip afm hf3scope:eqversion:12.0.0

Trust: 0.3

vendor:f5model:big-ip afm hf2scope:eqversion:12.0.0

Trust: 0.3

vendor:f5model:big-ip afm hf1scope:eqversion:12.0.0

Trust: 0.3

vendor:f5model:big-ip afm hf5scope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip afm hf4scope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip aam hf1scope:eqversion:12.1

Trust: 0.3

vendor:f5model:big-ip aam buildscope:eqversion:12.01.14.628

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip aam hf7scope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip aam hf6scope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:11.5.2

Trust: 0.3

vendor:f5model:big-ip aam hf10scope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:11.5

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:12.1.0

Trust: 0.3

vendor:f5model:big-ip aam hf3scope:eqversion:12.0.0

Trust: 0.3

vendor:f5model:big-ip aam hf2scope:eqversion:12.0.0

Trust: 0.3

vendor:f5model:big-ip aam hf1scope:eqversion:12.0.0

Trust: 0.3

vendor:f5model:big-ip aam hf5scope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip aam hf4scope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ipscope:eqversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip websafe hf2scope:neversion:12.1

Trust: 0.3

vendor:f5model:big-ip websafe hf4scope:neversion:12.0

Trust: 0.3

vendor:f5model:big-ip websafe hf1scope:neversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip websafe hf8scope:neversion:11.6

Trust: 0.3

vendor:f5model:big-ip webaccelerator hf2scope:neversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip pem hf2scope:neversion:12.1

Trust: 0.3

vendor:f5model:big-ip pem hf4scope:neversion:12.0

Trust: 0.3

vendor:f5model:big-ip pem hf1scope:neversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip pem hf8scope:neversion:11.6

Trust: 0.3

vendor:f5model:big-ip pem hf2scope:neversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip pem hf11scope:neversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip ltmscope:neversion:12.1.1

Trust: 0.3

vendor:f5model:big-ip ltm hf2scope:neversion:12.1

Trust: 0.3

vendor:f5model:big-ip ltm hf4scope:neversion:12.0

Trust: 0.3

vendor:f5model:big-ip ltm hf1scope:neversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip ltm hf8scope:neversion:11.6

Trust: 0.3

vendor:f5model:big-ip ltm hf2scope:neversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip ltm hf11scope:neversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip link controller hf2scope:neversion:12.1

Trust: 0.3

vendor:f5model:big-ip link controller hf4scope:neversion:12.0

Trust: 0.3

vendor:f5model:big-ip link controller hf1scope:neversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip link controller hf8scope:neversion:11.6

Trust: 0.3

vendor:f5model:big-ip link controller hf2scope:neversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip link controller hf11scope:neversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip gtm hf2scope:neversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip asm hf2scope:neversion:12.1

Trust: 0.3

vendor:f5model:big-ip asm hf4scope:neversion:12.0

Trust: 0.3

vendor:f5model:big-ip asm hf1scope:neversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip asm hf8scope:neversion:11.6

Trust: 0.3

vendor:f5model:big-ip asm hf2scope:neversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip asm hf11scope:neversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip apm hf2scope:neversion:12.1

Trust: 0.3

vendor:f5model:big-ip apm hf4scope:neversion:12.0

Trust: 0.3

vendor:f5model:big-ip apm hf1scope:neversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip apm hf8scope:neversion:11.6

Trust: 0.3

vendor:f5model:big-ip apm hf11scope:neversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip analytics hf2scope:neversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip afm hf2scope:neversion:12.1

Trust: 0.3

vendor:f5model:big-ip afm hf4scope:neversion:12.0

Trust: 0.3

vendor:f5model:big-ip afm hf1scope:neversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip afm hf8scope:neversion:11.6

Trust: 0.3

vendor:f5model:big-ip afm hf2scope:neversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip afm hf11scope:neversion:11.5.1

Trust: 0.3

vendor:f5model:big-ip aam hf2scope:neversion:12.1

Trust: 0.3

vendor:f5model:big-ip aam hf4scope:neversion:12.0

Trust: 0.3

vendor:f5model:big-ip aam hf1scope:neversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip aam hf8scope:neversion:11.6

Trust: 0.3

vendor:f5model:big-ip aam hf2scope:neversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip aam hf11scope:neversion:11.5.1

Trust: 0.3

sources: BID: 93325 // JVNDB: JVNDB-2016-005087 // CNNVD: CNNVD-201610-025 // NVD: CVE-2016-5700

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-5700
value: CRITICAL

Trust: 1.0

NVD: CVE-2016-5700
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-201610-025
value: CRITICAL

Trust: 0.6

VULHUB: VHN-94519
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2016-5700
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-94519
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2016-5700
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-94519 // JVNDB: JVNDB-2016-005087 // CNNVD: CNNVD-201610-025 // NVD: CVE-2016-5700

PROBLEMTYPE DATA

problemtype:CWE-284

Trust: 1.1

problemtype:CWE-Other

Trust: 0.8

sources: VULHUB: VHN-94519 // JVNDB: JVNDB-2016-005087 // NVD: CVE-2016-5700

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201610-025

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-201610-025

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-005087

PATCH

title:SOL35520031: BIG-IP virtual server with HTTP Explicit Proxy and/or SOCKS vulnerability CVE-2016-5700url:https://support.f5.com/kb/en-us/solutions/public/k/35/sol35520031.html

Trust: 0.8

title:F5 BIG-IP Remediation measures for remote security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=64464

Trust: 0.6

sources: JVNDB: JVNDB-2016-005087 // CNNVD: CNNVD-201610-025

EXTERNAL IDS

db:NVDid:CVE-2016-5700

Trust: 2.8

db:SECTRACKid:1036928

Trust: 1.7

db:BIDid:93325

Trust: 1.4

db:JVNDBid:JVNDB-2016-005087

Trust: 0.8

db:CNNVDid:CNNVD-201610-025

Trust: 0.7

db:VULHUBid:VHN-94519

Trust: 0.1

sources: VULHUB: VHN-94519 // BID: 93325 // JVNDB: JVNDB-2016-005087 // CNNVD: CNNVD-201610-025 // NVD: CVE-2016-5700

REFERENCES

url:https://support.f5.com/kb/en-us/solutions/public/k/35/sol35520031.html

Trust: 2.0

url:http://www.securitytracker.com/id/1036928

Trust: 1.7

url:http://www.securityfocus.com/bid/93325

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-5700

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2016-5700

Trust: 0.8

url:http://www.f5.com/products/big-ip/

Trust: 0.3

sources: VULHUB: VHN-94519 // BID: 93325 // JVNDB: JVNDB-2016-005087 // CNNVD: CNNVD-201610-025 // NVD: CVE-2016-5700

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 93325

SOURCES

db:VULHUBid:VHN-94519
db:BIDid:93325
db:JVNDBid:JVNDB-2016-005087
db:CNNVDid:CNNVD-201610-025
db:NVDid:CVE-2016-5700

LAST UPDATE DATE

2024-11-23T22:52:39.027000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-94519date:2016-11-28T00:00:00
db:BIDid:93325date:2016-10-10T01:04:00
db:JVNDBid:JVNDB-2016-005087date:2016-10-06T00:00:00
db:CNNVDid:CNNVD-201610-025date:2016-10-08T00:00:00
db:NVDid:CVE-2016-5700date:2024-11-21T02:54:50.933

SOURCES RELEASE DATE

db:VULHUBid:VHN-94519date:2016-10-03T00:00:00
db:BIDid:93325date:2016-09-28T00:00:00
db:JVNDBid:JVNDB-2016-005087date:2016-10-06T00:00:00
db:CNNVDid:CNNVD-201610-025date:2016-10-08T00:00:00
db:NVDid:CVE-2016-5700date:2016-10-03T16:09:13.790