CVE Vulnerabilities

CVE-2016-9250

Published: May 10, 2017 | Modified: Jun 06, 2019
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

In F5 BIG-IP 11.2.1, 11.4.0 through 11.6.1, and 12.0.0 through 12.1.2, an unauthenticated user with access to the control plane may be able to delete arbitrary files through an undisclosed mechanism.

Affected Software

Name Vendor Start Version End Version
Big-ip_local_traffic_manager F5 11.2.1 (including) 11.2.1 (including)
Big-ip_local_traffic_manager F5 11.4.0 (including) 11.4.0 (including)
Big-ip_local_traffic_manager F5 11.4.1 (including) 11.4.1 (including)
Big-ip_local_traffic_manager F5 11.5.0 (including) 11.5.0 (including)
Big-ip_local_traffic_manager F5 11.5.1 (including) 11.5.1 (including)
Big-ip_local_traffic_manager F5 11.5.2 (including) 11.5.2 (including)
Big-ip_local_traffic_manager F5 11.5.3 (including) 11.5.3 (including)
Big-ip_local_traffic_manager F5 11.5.4 (including) 11.5.4 (including)
Big-ip_local_traffic_manager F5 11.6.0 (including) 11.6.0 (including)
Big-ip_local_traffic_manager F5 11.6.1 (including) 11.6.1 (including)
Big-ip_local_traffic_manager F5 12.0.0 (including) 12.0.0 (including)
Big-ip_local_traffic_manager F5 12.1.0 (including) 12.1.0 (including)
Big-ip_local_traffic_manager F5 12.1.1 (including) 12.1.1 (including)
Big-ip_local_traffic_manager F5 12.1.2 (including) 12.1.2 (including)

References