CVE-2017-6143Improper Certificate Validation in F5 Big-ip Advanced Firewall Manager

Severity
5.4MEDIUMNVD
EPSS
0.1%
top 70.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateMay 14

Description

X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the remote server's identity is not properly validated in F5 BIG-IP 12.0.0-12.1.2, 11.6.0-11.6.2, or 11.5.0-11.5.5.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:NExploitability: 2.2 | Impact: 2.7

Affected Packages2 packages

NVDf5/big-ip_advanced_firewall_manager11.5.111.5.5+2

🔴Vulnerability Details

2
GHSA
GHSA-p7pq-m3xx-w733: X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the r2022-05-14
CVEList
CVE-2017-6143: X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the r2018-04-13

📋Vendor Advisories

1
F5
CVE-2017-6143: X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence f...2018-04-13
CVE-2017-6143 — Improper Certificate Validation in F5 | cvebase