CVE-2017-6130
published 2017-04-06CVE-2017-6130: F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attack when deployed using the Dynamic…
PriorityP433high7.4CVSS 3.0
AVNACLPRNUIRSCCNIHAN
EPSS
1.15%
63.2th percentile
F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attack when deployed using the Dynamic Domain Bypass (DDB) feature feature plus SNAT Auto Map option for egress traffic.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | ssl_intercept_iapp | — | — |
| f5 | ssl_intercept_iapp | — | — |
| f5 | ssl_intercept_iapp | — | — |
| f5 | ssl_orchestrator | — | — |
| f5 | ssl_orchestrator | — | — |
| f5_networks | ssl_intercept_iapp_1.5.0_1.5.7_and_ssl_orchestrator_2.0 | — | — |
CVSS provenance
nvdv3.07.4HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2017-6130: F5 SSL Intercept iApp 1
vendor_f5·2017-04-06·CVSS 7.4
CVE-2017-6130 [HIGH] CWE-918 CVE-2017-6130: F5 SSL Intercept iApp 1
CVE-2017-6130: F5 SSL Intercept iApp 1
F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attack when deployed using the Dynamic Domain Bypass (DDB) feature feature plus SNAT Auto Map option for egress traffic.
Affected Products: Ssl Intercept Iapp, Ssl Orchestrator
Affected Versions: 1.5.0; 1.5.7; 2.0
F5 Advisory Articles: K23001529
F5 References: https://support.f5.com/csp/article/K23001529
GHSA
GHSA-xj4r-whfg-77cr: F5 SSL Intercept iApp 1
ghsa_unreviewed·2022-05-17
CVE-2017-6130 [HIGH] CWE-918 GHSA-xj4r-whfg-77cr: F5 SSL Intercept iApp 1
F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attack when deployed using the Dynamic Domain Bypass (DDB) feature feature plus SNAT Auto Map option for egress traffic.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-04-06
Published