CVE-2017-6157F5 Big-ip Link Controller vulnerability

4 documents4 sources
Severity
8.1HIGHNVD
EPSS
6.9%
top 8.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 13

Description

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 12.0.0 to 12.1.1, 11.6.0 to 11.6.1, 11.5.0 - 11.5.4, virtual servers with a configuration using the HTTP Explicit Proxy functionality and/or SOCKS profile are vulnerable to an unauthenticated, remote attack that allows modification of BIG-IP system configuration, extraction of sensitive system files, and/or possible remote command execution on the BIG-IP system.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages8 packages

NVDf5/big-ip_link_controller11.5.011.5.4+5
NVDf5/big-ip_websafe5 versions+4
NVDf5/big-ip_access_policy_manager11.5.011.5.4+5
NVDf5/big-ip_local_traffic_manager11.5.011.5.4+5
NVDf5/big-ip_advanced_firewall_manager11.5.011.5.4+5

🔴Vulnerability Details

2
GHSA
GHSA-hp65-qghh-rm7p: In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 122022-05-13
CVEList
CVE-2017-6157: In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 122017-10-27

📋Vendor Advisories

1
F5
CVE-2017-6157: In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 122017-10-27
CVE-2017-6157 — F5 Big-ip Link Controller vulnerability | cvebase