CVE-2017-6152
published 2018-03-08CVE-2017-6152: A local user on F5 BIG-IQ Centralized Management 5.1.0-5.2.0 with the Access Manager role has privileges to change the passwords of other users on the system…
PriorityP427medium6.7CVSS 3.0
AVLACLPRHUINSUCHIHAH
EPSS
0.32%
24.0th percentile
A local user on F5 BIG-IQ Centralized Management 5.1.0-5.2.0 with the Access Manager role has privileges to change the passwords of other users on the system, including the local admin account password.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-iq | — | — |
| f5 | big-iq_centralized_management | 5.1.0 – 5.2.0 | — |
| f5_networks_inc | big-iq_centralized_management | — | — |
CVSS provenance
nvdv3.06.7MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2017-6152: A local user on F5 BIG-IQ Centralized Management 5
vendor_f5·2018-03-08·CVSS 6.7
CVE-2017-6152 [MEDIUM] CWE-269 CVE-2017-6152: A local user on F5 BIG-IQ Centralized Management 5
CVE-2017-6152: A local user on F5 BIG-IQ Centralized Management 5
A local user on F5 BIG-IQ Centralized Management 5.1.0-5.2.0 with the Access Manager role has privileges to change the passwords of other users on the system, including the local admin account password.
Affected Products: BIG-IQ
Affected Versions: 5.1.0 - 5.2.0
F5 Advisory Articles: K35195140
F5 References: https://support.f5.com/csp/article/K35195140
GHSA
GHSA-8jrf-3p79-h4f4: A local user on F5 BIG-IQ Centralized Management 5
ghsa_unreviewed·2022-05-13
CVE-2017-6152 [MEDIUM] CWE-269 GHSA-8jrf-3p79-h4f4: A local user on F5 BIG-IQ Centralized Management 5
A local user on F5 BIG-IQ Centralized Management 5.1.0-5.2.0 with the Access Manager role has privileges to change the passwords of other users on the system, including the local admin account password.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-03-08
Published