ID

VAR-201904-0098


CVE

CVE-2019-6609


TITLE

plural BIG-IP Vulnerabilities related to certificate and password management in products

Trust: 0.8

sources: JVNDB: JVNDB-2019-003425

DESCRIPTION

Platform dependent weakness. This issue only impacts iSeries platforms. On these platforms, in BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator) versions 14.0.0-14.1.0.1, 13.0.0-13.1.1.3, and 12.1.1 HF2-12.1.4, the secureKeyCapable attribute was not set which causes secure vault to not use the F5 hardware support to store the unit key. Instead the unit key is stored in plaintext on disk as would be the case for Z100 systems. Additionally this causes the unit key to be stored in UCS files taken on these platforms. plural BIG-IP The product contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Multiple BIG-IP Products are prone to an information-disclosure vulnerability. Successfully exploiting this issue may allow attackers to obtain sensitive information. This may lead to other attacks. F5 BIG-IP is an application delivery platform integrated with network traffic management, application security management, load balancing and other functions of the US company F5. A trust management issue vulnerability exists in the F5 BIG-IP. This vulnerability stems from the lack of an effective trust management mechanism in network systems or products. Attackers can use default passwords or hard-coded passwords, hard-coded certificates, etc. to attack affected components. The following versions are affected: F5 BIG-IP version 14.0.0 to 14.1.0.1, 13.0.0 to 13.1.1.3, 12.1.1 HF2 to 12.1.4

Trust: 2.07

sources: NVD: CVE-2019-6609 // JVNDB: JVNDB-2019-003425 // BID: 108043 // VULHUB: VHN-158044 // VULMON: CVE-2019-6609

AFFECTED PRODUCTS

vendor:f5model:big-ip webacceleratorscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:ltversion:13.1.1.4

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:12.1.1

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:ltversion:12.1.4.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:12.1.1

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:12.1.4.1

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:12.1.4.1

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:14.1.0.2

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:ltversion:12.1.4.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:12.1.4.1

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:eqversion:12.1.1

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:ltversion:14.1.0.2

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:13.1.1.4

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:12.1.4.1

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:eqversion:12.1.1

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:ltversion:14.1.0.2

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:ltversion:13.1.1.4

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:12.1.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:ltversion:14.1.0.2

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:14.1.0.2

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:ltversion:14.1.0.2

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:14.1.0.2

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:ltversion:13.1.1.4

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:ltversion:14.1.0.2

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:13.1.1.4

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:ltversion:13.1.1.4

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:13.1.1.4

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:12.1.1

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:14.1.0.2

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:12.1.1

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:ltversion:13.1.1.4

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:14.1.0.2

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:ltversion:14.1.0.2

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:14.1.0.2

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:12.1.4.1

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:13.1.1.4

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:14.0.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:12.1.1

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip webaccelerator12.1.1scope:eqversion:hf2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:13.1.1.4

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:12.1.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:13.1.1.4

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:ltversion:13.1.1.4

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:ltversion:12.1.4.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:12.1.1

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:gteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:12.1.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:14.1.0.2

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:ltversion:12.1.4.1

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:ltversion:12.1.4.1

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:12.1.2

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:ltversion:12.1.4.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:13.1.1.4

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:13.0.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:12.1.4.1

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:eqversion:12.1.1

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:12.1.4.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip analyticsscope: - version: -

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip application security managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip domain name systemscope: - version: -

Trust: 0.8

vendor:f5model:big-ip edge gatewayscope: - version: -

Trust: 0.8

vendor:f5model:big-ip fraud protection servicescope: - version: -

Trust: 0.8

vendor:f5model:big-ip global traffic managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:ltversion:4.76

Trust: 0.8

vendor:f5model:big-ip webacceleratorscope:eqversion:14.1

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:14.0

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:13.1.1

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:13.1

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:13.0.1

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:12.1.4

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:12.1.3

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:14.1.0.1

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:14.0.0.3

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:13.1.1.3

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:13.1.1.2

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:13.1.0.8

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:13.1.0.6

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:13.1.0.5

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:13.1.0.4

Trust: 0.3

vendor:f5model:big-ip webaccelerator hf2scope:eqversion:12.1.1

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:14.1

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:14.0

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:13.1.1

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:13.1

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:13.0.1

Trust: 0.3

vendor:f5model:big-ip pem hf3scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip pem hf2scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:12.1.4

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:12.1.3

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip pem hf2scope:eqversion:12.1.1

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:14.1.0.1

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:14.0.0.3

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:13.1.1.3

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:13.1.1.2

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:13.1.0.8

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:13.1.0.6

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:13.1.0.5

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:13.1.0.4

Trust: 0.3

vendor:f5model:big-ip pem hf1scope:eqversion:13.0.0

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:14.1

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:14.0.2

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:14.0

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:13.1.1

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:13.1

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:13.0.1

Trust: 0.3

vendor:f5model:big-ip ltm hf3scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip ltm hf2scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip ltm hf1scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:12.1.4

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:12.1.3

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:14.1.0.1

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:14.0.0.3

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:13.1.1.3

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:13.1.1.2

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:13.1.0.8

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:13.1.0.6

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:13.1.0.5

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:13.1.0.4

Trust: 0.3

vendor:f5model:big-ip ltm hf2scope:eqversion:12.1.1

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:14.1

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:14.0

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:13.1.1

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:13.1

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:13.0.1

Trust: 0.3

vendor:f5model:big-ip link controller hf3scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip link controller hf2scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:12.1.4

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:12.1.3

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip link controller hf2scope:eqversion:12.1.1

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:14.1.0.1

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:14.0.0.3

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:13.1.1.3

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:13.1.1.2

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:13.1.0.8

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:13.1.0.6

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:13.1.0.5

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:13.1.0.4

Trust: 0.3

vendor:f5model:big-ip link controller hf1scope:eqversion:13.0.0

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:14.1

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:14.0

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:13.1.1

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:13.1

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:13.0.1

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:12.1.4

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:12.1.3

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip gtm hf2scope:eqversion:12.1.1

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:14.1.0.1

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:14.0.0.3

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:13.1.1.3

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:13.1.1.2

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:13.1.0.8

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:13.1.0.6

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:13.1.0.5

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:13.1.0.4

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:13.0.0

Trust: 0.3

vendor:f5model:big-ip fpsscope:eqversion:14.1

Trust: 0.3

vendor:f5model:big-ip fpsscope:eqversion:14.0

Trust: 0.3

vendor:f5model:big-ip fpsscope:eqversion:13.1.1

Trust: 0.3

vendor:f5model:big-ip fpsscope:eqversion:13.1

Trust: 0.3

vendor:f5model:big-ip fpsscope:eqversion:13.0.1

Trust: 0.3

vendor:f5model:big-ip fpsscope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip fpsscope:eqversion:12.1.4

Trust: 0.3

vendor:f5model:big-ip fpsscope:eqversion:12.1.3

Trust: 0.3

vendor:f5model:big-ip fpsscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip fpsscope:eqversion:14.1.0.1

Trust: 0.3

vendor:f5model:big-ip fpsscope:eqversion:14.0.0.3

Trust: 0.3

vendor:f5model:big-ip fpsscope:eqversion:13.1.1.3

Trust: 0.3

vendor:f5model:big-ip fpsscope:eqversion:13.1.1.2

Trust: 0.3

vendor:f5model:big-ip fpsscope:eqversion:13.1.0.8

Trust: 0.3

vendor:f5model:big-ip fps hf2scope:eqversion:12.1.1

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:14.1

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:14.0

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:13.1.1

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:13.1

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:13.0.1

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:12.1.4

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:12.1.3

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:14.0.0.3

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:13.1.1.2

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:13.1.0.6

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:13.1.0.5

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:14.1

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:14.0

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:13.1.1

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:13.1

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:13.0.1

Trust: 0.3

vendor:f5model:big-ip dns hf3scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip dns hf2scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip dns hf1scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:12.1.4

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:12.1.3

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:14.1.0.1

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:14.0.0.3

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:13.1.1.3

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:13.1.1.2

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:13.1.0.8

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:13.1.0.7

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:13.1.0.6

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:13.1.0.5

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:13.1.0.4

Trust: 0.3

vendor:f5model:big-ip dns hf2scope:eqversion:12.1.1

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:14.1

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:14.0

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:13.1.1

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:13.1

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:13.0.1

Trust: 0.3

vendor:f5model:big-ip asm hf3scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip asm hf2scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip asm hf1scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:12.1.4

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:12.1.3

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:14.1.0.1

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:14.0.0.3

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:14.0.0.2

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:13.1.1.3

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:13.1.1.2

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:13.1.0.8

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:13.1.0.6

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:13.1.0.5

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:13.1.0.4

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:13.1.0.2

Trust: 0.3

vendor:f5model:big-ip asm hf2scope:eqversion:12.1.1

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:14.1

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:14.0

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:13.1.1

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:13.1

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:13.0.1

Trust: 0.3

vendor:f5model:big-ip apm hf3scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip apm hf1scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:12.1.4

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:12.1.3

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:14.1.0.1

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:13.1.1.3

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:13.1.1.2

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:13.1.0.8

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:13.1.0.6

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:13.1.0.5

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:13.1.0.4

Trust: 0.3

vendor:f5model:big-ip apm hf2scope:eqversion:12.1.1

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:14.1

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:14.0

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:13.1.1

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:13.1

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:13.0.1

Trust: 0.3

vendor:f5model:big-ip analytics hf3scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip analytics hf2scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip analytics hf1scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:12.1.4

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:12.1.3

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:14.1.0.1

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:14.0.0.3

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:13.1.1.3

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:13.1.0.8

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:13.1.0.6

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:13.1.0.5

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:13.1.0.4

Trust: 0.3

vendor:f5model:big-ip analytics hf2scope:eqversion:12.1.1

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:14.1

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:14.0

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:13.1.1

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:13.1

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:13.0.1

Trust: 0.3

vendor:f5model:big-ip afm hf3scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip afm hf2scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip afm hf1scope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:12.1.4

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:12.1.3

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:14.1.0.1

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:13.1.1.3

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:13.1.1.2

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:13.1.0.8

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:13.1.0.6

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:13.1.0.5

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:13.1.0.4

Trust: 0.3

vendor:f5model:big-ip afm hf2scope:eqversion:12.1.1

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:14.1

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:14.0

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:13.1.1

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:13.1

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:13.0.1

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:13.0

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:12.1.4

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:12.1.3

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:14.1.0.1

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:13.1.1.3

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:13.1.1.2

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:13.1.0.8

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:13.1.0.6

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:13.1.0.5

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:13.1.0.4

Trust: 0.3

vendor:f5model:big-ip aam hf2scope:eqversion:12.1.1

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:neversion:14.1.0.2

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:neversion:13.1.1.4

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:neversion:12.1.4.1

Trust: 0.3

vendor:f5model:big-ip pemscope:neversion:14.1.0.2

Trust: 0.3

vendor:f5model:big-ip pemscope:neversion:13.1.1.4

Trust: 0.3

vendor:f5model:big-ip pemscope:neversion:12.1.4.1

Trust: 0.3

vendor:f5model:big-ip ltmscope:neversion:14.1.0.2

Trust: 0.3

vendor:f5model:big-ip ltmscope:neversion:13.1.1.4

Trust: 0.3

vendor:f5model:big-ip ltmscope:neversion:12.1.4.1

Trust: 0.3

vendor:f5model:big-ip link controllerscope:neversion:14.1.0.2

Trust: 0.3

vendor:f5model:big-ip link controllerscope:neversion:13.1.1.4

Trust: 0.3

vendor:f5model:big-ip link controllerscope:neversion:12.1.4.1

Trust: 0.3

vendor:f5model:big-ip gtmscope:neversion:14.1.0.2

Trust: 0.3

vendor:f5model:big-ip gtmscope:neversion:13.1.1.4

Trust: 0.3

vendor:f5model:big-ip fpsscope:neversion:14.1.0.2

Trust: 0.3

vendor:f5model:big-ip fpsscope:neversion:13.1.1.4

Trust: 0.3

vendor:f5model:big-ip fpsscope:neversion:12.1.4.1

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:neversion:13.1.1.4

Trust: 0.3

vendor:f5model:big-ip dnsscope:neversion:14.1.0.2

Trust: 0.3

vendor:f5model:big-ip dnsscope:neversion:13.1.1.4

Trust: 0.3

vendor:f5model:big-ip dnsscope:neversion:12.1.4.1

Trust: 0.3

vendor:f5model:big-ip asmscope:neversion:14.1.0.2

Trust: 0.3

vendor:f5model:big-ip asmscope:neversion:13.1.1.4

Trust: 0.3

vendor:f5model:big-ip asmscope:neversion:12.1.4.1

Trust: 0.3

vendor:f5model:big-ip apmscope:neversion:14.1.0.2

Trust: 0.3

vendor:f5model:big-ip apmscope:neversion:13.1.1.4

Trust: 0.3

vendor:f5model:big-ip apmscope:neversion:12.1.4.1

Trust: 0.3

vendor:f5model:big-ip analyticsscope:neversion:14.1.0.2

Trust: 0.3

vendor:f5model:big-ip analyticsscope:neversion:13.1.1.4

Trust: 0.3

vendor:f5model:big-ip analyticsscope:neversion:12.1.4.1

Trust: 0.3

vendor:f5model:big-ip afmscope:neversion:14.1.0.2

Trust: 0.3

vendor:f5model:big-ip afmscope:neversion:13.1.1.4

Trust: 0.3

vendor:f5model:big-ip afmscope:neversion:12.1.4.1

Trust: 0.3

vendor:f5model:big-ip aamscope:neversion:14.1.0.2

Trust: 0.3

vendor:f5model:big-ip aamscope:neversion:13.1.1.4

Trust: 0.3

vendor:f5model:big-ip aamscope:neversion:12.1.4.1

Trust: 0.3

sources: BID: 108043 // JVNDB: JVNDB-2019-003425 // NVD: CVE-2019-6609

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-6609
value: CRITICAL

Trust: 1.0

NVD: CVE-2019-6609
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-201904-578
value: CRITICAL

Trust: 0.6

VULHUB: VHN-158044
value: MEDIUM

Trust: 0.1

VULMON: CVE-2019-6609
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2019-6609
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-158044
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-6609
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-158044 // VULMON: CVE-2019-6609 // JVNDB: JVNDB-2019-003425 // CNNVD: CNNVD-201904-578 // NVD: CVE-2019-6609

PROBLEMTYPE DATA

problemtype:CWE-522

Trust: 1.1

problemtype:CWE-255

Trust: 0.9

sources: VULHUB: VHN-158044 // JVNDB: JVNDB-2019-003425 // NVD: CVE-2019-6609

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201904-578

TYPE

trust management problem

Trust: 0.6

sources: CNNVD: CNNVD-201904-578

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-003425

PATCH

title:K18535734url:https://support.f5.com/csp/article/K18535734

Trust: 0.8

title:F5 BIG-IP Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=91390

Trust: 0.6

sources: JVNDB: JVNDB-2019-003425 // CNNVD: CNNVD-201904-578

EXTERNAL IDS

db:NVDid:CVE-2019-6609

Trust: 2.9

db:JVNDBid:JVNDB-2019-003425

Trust: 0.8

db:CNNVDid:CNNVD-201904-578

Trust: 0.7

db:AUSCERTid:ESB-2019.1250

Trust: 0.6

db:BIDid:108043

Trust: 0.3

db:VULHUBid:VHN-158044

Trust: 0.1

db:VULMONid:CVE-2019-6609

Trust: 0.1

sources: VULHUB: VHN-158044 // VULMON: CVE-2019-6609 // BID: 108043 // JVNDB: JVNDB-2019-003425 // CNNVD: CNNVD-201904-578 // NVD: CVE-2019-6609

REFERENCES

url:https://support.f5.com/csp/article/k18535734

Trust: 2.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-6609

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-6609

Trust: 0.8

url:https://vigilance.fr/vulnerability/f5-big-ip-privilege-escalation-via-secure-vault-unit-key-29007

Trust: 0.6

url:https://www.auscert.org.au/bulletins/78914

Trust: 0.6

url:http://www.f5.com/products/big-ip/

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/522.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-158044 // VULMON: CVE-2019-6609 // BID: 108043 // JVNDB: JVNDB-2019-003425 // CNNVD: CNNVD-201904-578 // NVD: CVE-2019-6609

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 108043

SOURCES

db:VULHUBid:VHN-158044
db:VULMONid:CVE-2019-6609
db:BIDid:108043
db:JVNDBid:JVNDB-2019-003425
db:CNNVDid:CNNVD-201904-578
db:NVDid:CVE-2019-6609

LAST UPDATE DATE

2024-11-23T22:55:37.952000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-158044date:2020-08-24T00:00:00
db:VULMONid:CVE-2019-6609date:2020-08-24T00:00:00
db:BIDid:108043date:2019-04-10T00:00:00
db:JVNDBid:JVNDB-2019-003425date:2019-05-16T00:00:00
db:CNNVDid:CNNVD-201904-578date:2020-08-25T00:00:00
db:NVDid:CVE-2019-6609date:2024-11-21T04:46:47.907

SOURCES RELEASE DATE

db:VULHUBid:VHN-158044date:2019-04-15T00:00:00
db:VULMONid:CVE-2019-6609date:2019-04-15T00:00:00
db:BIDid:108043date:2019-04-10T00:00:00
db:JVNDBid:JVNDB-2019-003425date:2019-05-16T00:00:00
db:CNNVDid:CNNVD-201904-578date:2019-04-11T00:00:00
db:NVDid:CVE-2019-6609date:2019-04-15T15:29:00.920