CVE-2017-6143
published 2018-04-13CVE-2017-6143: X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the remote…
medium5.4CVSS 3.0
AVNACHPRNUINSCCLILAN
X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the remote server's identity is not properly validated in F5 BIG-IP 12.0.0-12.1.2, 11.6.0-11.6.2, or 11.5.0-11.5.5.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_advanced_firewall_manager | 11.5.1 – 11.5.5 | — |
| f5 | big-ip_advanced_firewall_manager | 11.6.1 – 11.6.2 | — |
| f5 | big-ip_advanced_firewall_manager | 12.1.0 – 12.1.2 | — |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_application_security_manager | <= 12.1.2 | — |
| f5 | big-ip_application_security_manager | 11.5.1 – 11.5.5 | — |
| f5 | big-ip_application_security_manager | 11.6.1 – 11.6.2 | — |
| f5 | big-ip_asm | — | — |
GHSA
GHSA-p7pq-m3xx-w733: X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the r
ghsa_unreviewed·2022-05-14
CVE-2017-6143 [MEDIUM] CWE-295 GHSA-p7pq-m3xx-w733: X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the r
X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the remote server's identity is not properly validated in F5 BIG-IP 12.0.0-12.1.2, 11.6.0-11.6.2, or 11.5.0-11.5.5.
F5
CVE-2017-6143: X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence f...
vendor_f5·2018-04-13·CVSS 5.4
CVE-2017-6143 [MEDIUM] CWE-295 CVE-2017-6143: X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence f...
CVE-2017-6143: X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence f...
X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the remote server's identity is not properly validated in F5 BIG-IP 12.0.0-12.1.2, 11.6.0-11.6.2, or 11.5.0-11.5.5.
Affected Products: BIG-IP AFM, BIG-IP ASM
Affected Versions: 11.5.1 - 11.5.5; 11.6.1 - 11.6.2; 12.1.0 - 12.1.2
F5 Advisory Articles: K11464209
F5 References: https://support.f5.com/csp/article/K11464209
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-04-13
Published