CVE-2017-6143
published 2018-04-13CVE-2017-6143: X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the remote…
PriorityP425medium5.4CVSS 3.0
AVNACHPRNUINSCCLILAN
EPSS
0.43%
34.6th percentile
X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the remote server's identity is not properly validated in F5 BIG-IP 12.0.0-12.1.2, 11.6.0-11.6.2, or 11.5.0-11.5.5.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_advanced_firewall_manager | 11.5.1 – 11.5.5 | — |
| f5 | big-ip_advanced_firewall_manager | 11.6.1 – 11.6.2 | — |
| f5 | big-ip_advanced_firewall_manager | 12.1.0 – 12.1.2 | — |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_application_security_manager | <= 12.1.2 | — |
| f5 | big-ip_application_security_manager | 11.5.1 – 11.5.5 | — |
| f5 | big-ip_application_security_manager | 11.6.1 – 11.6.2 | — |
| f5 | big-ip_asm | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p7pq-m3xx-w733: X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the r
ghsa_unreviewed·2022-05-14
CVE-2017-6143 [MEDIUM] CWE-295 GHSA-p7pq-m3xx-w733: X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the r
X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the remote server's identity is not properly validated in F5 BIG-IP 12.0.0-12.1.2, 11.6.0-11.6.2, or 11.5.0-11.5.5.
F5
CVE-2017-6143: X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence f...
vendor_f5·2018-04-13·CVSS 5.4
CVE-2017-6143 [MEDIUM] CWE-295 CVE-2017-6143: X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence f...
CVE-2017-6143: X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence f...
X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the remote server's identity is not properly validated in F5 BIG-IP 12.0.0-12.1.2, 11.6.0-11.6.2, or 11.5.0-11.5.5.
Affected Products: BIG-IP AFM, BIG-IP ASM
Affected Versions: 11.5.1 - 11.5.5; 11.6.1 - 11.6.2; 12.1.0 - 12.1.2
F5 Advisory Articles: K11464209
F5 References: https://support.f5.com/csp/article/K11464209
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-04-13
Published