CVE-2017-6143 — Improper Certificate Validation in F5 Big-ip Advanced Firewall Manager
Severity
5.4MEDIUMNVD
EPSS
0.1%
top 70.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateMay 14
Description
X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the remote server's identity is not properly validated in F5 BIG-IP 12.0.0-12.1.2, 11.6.0-11.6.2, or 11.5.0-11.5.5.
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:NExploitability: 2.2 | Impact: 2.7
Affected Packages2 packages
🔴Vulnerability Details
2GHSA▶
GHSA-p7pq-m3xx-w733: X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the r↗2022-05-14
CVEList▶
CVE-2017-6143: X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the r↗2018-04-13
📋Vendor Advisories
1F5▶
CVE-2017-6143: X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence f...↗2018-04-13