CVE Vulnerabilities

CVE-2019-6642

Published: Jul 01, 2019 | Modified: Nov 07, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, authenticated users with the ability to upload files (via scp, for example) can escalate their privileges to allow root shell access from within the TMOS Shell (tmsh) interface. The tmsh interface allows users to execute a secondary program via tools like sftp or scp.

Affected Software

Name Vendor Start Version End Version
Big-ip_access_policy_manager F5 11.5.2 (including) 11.6.4 (including)
Big-ip_access_policy_manager F5 12.1.0 (including) 12.1.4.2 (including)
Big-ip_access_policy_manager F5 13.0.0 (including) 13.1.1.5 (including)
Big-ip_access_policy_manager F5 14.0.0 (including) 14.1.0.5 (including)
Big-ip_access_policy_manager F5 15.0.0 (including) 15.0.0 (including)

References