CVE Vulnerabilities

CVE-2019-6646

Published: Sep 04, 2019 | Modified: Aug 24, 2020
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

On BIG-IP 11.5.2-11.6.4 and Enterprise Manager 3.1.1, REST users with guest privileges may be able to escalate their privileges and run commands with admin privileges.

Affected Software

Name Vendor Start Version End Version
Big-ip_access_policy_manager F5 11.5.2 (including) 11.6.4 (including)
Big-ip_access_policy_manager F5 12.0.0 (including) 12.0.0 (including)
Big-ip_advanced_firewall_manager F5 11.5.2 (including) 11.6.4 (including)
Big-ip_advanced_firewall_manager F5 12.0.0 (including) 12.0.0 (including)
Big-ip_analytics F5 11.5.2 (including) 11.6.4 (including)
Big-ip_analytics F5 12.0.0 (including) 12.0.0 (including)
Big-ip_application_acceleration_manager F5 11.5.2 (including) 11.6.4 (including)
Big-ip_application_acceleration_manager F5 12.0.0 (including) 12.0.0 (including)
Big-ip_application_security_manager F5 11.5.2 (including) 11.6.4 (including)
Big-ip_application_security_manager F5 12.0.0 (including) 12.0.0 (including)
Big-ip_domain_name_system F5 11.5.2 (including) 11.6.4 (including)
Big-ip_domain_name_system F5 12.0.0 (including) 12.0.0 (including)
Big-ip_edge_gateway F5 11.5.2 (including) 11.6.4 (including)
Big-ip_edge_gateway F5 12.0.0 (including) 12.0.0 (including)
Big-ip_fraud_protection_service F5 11.5.2 (including) 11.6.4 (including)
Big-ip_fraud_protection_service F5 12.0.0 (including) 12.0.0 (including)
Big-ip_global_traffic_manager F5 11.5.2 (including) 11.6.4 (including)
Big-ip_global_traffic_manager F5 12.0.0 (including) 12.0.0 (including)
Big-ip_link_controller F5 11.5.2 (including) 11.6.4 (including)
Big-ip_link_controller F5 12.0.0 (including) 12.0.0 (including)
Big-ip_local_traffic_manager F5 11.5.2 (including) 11.6.4 (including)
Big-ip_local_traffic_manager F5 12.0.0 (including) 12.0.0 (including)
Big-ip_policy_enforcement_manager F5 11.5.2 (including) 11.6.4 (including)
Big-ip_policy_enforcement_manager F5 12.0.0 (including) 12.0.0 (including)
Big-ip_webaccelerator F5 11.5.2 (including) 11.6.4 (including)
Big-ip_webaccelerator F5 12.0.0 (including) 12.0.0 (including)
Enterprise_manager F5 3.1.1 (including) 3.1.1 (including)

References