CVE Vulnerabilities

CVE-2016-9250

Published: May 10, 2017 | Modified: Apr 20, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In F5 BIG-IP 11.2.1, 11.4.0 through 11.6.1, and 12.0.0 through 12.1.2, an unauthenticated user with access to the control plane may be able to delete arbitrary files through an undisclosed mechanism.

Affected Software

NameVendorStart VersionEnd Version
Big-ip_local_traffic_managerF511.2.1 (including)11.2.1 (including)
Big-ip_local_traffic_managerF511.4.0 (including)11.4.0 (including)
Big-ip_local_traffic_managerF511.4.1 (including)11.4.1 (including)
Big-ip_local_traffic_managerF511.5.0 (including)11.5.0 (including)
Big-ip_local_traffic_managerF511.5.1 (including)11.5.1 (including)
Big-ip_local_traffic_managerF511.5.2 (including)11.5.2 (including)
Big-ip_local_traffic_managerF511.5.3 (including)11.5.3 (including)
Big-ip_local_traffic_managerF511.5.4 (including)11.5.4 (including)
Big-ip_local_traffic_managerF511.6.0 (including)11.6.0 (including)
Big-ip_local_traffic_managerF511.6.1 (including)11.6.1 (including)
Big-ip_local_traffic_managerF512.0.0 (including)12.0.0 (including)
Big-ip_local_traffic_managerF512.1.0 (including)12.1.0 (including)
Big-ip_local_traffic_managerF512.1.1 (including)12.1.1 (including)
Big-ip_local_traffic_managerF512.1.2 (including)12.1.2 (including)

References