cbcvebase.
CVE-2017-6167
published 2017-12-21

CVE-2017-6167: In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, race conditions in iControl…

high7.5CVSS 3.0
AVNACHPRLUINSUCHIHAH
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, race conditions in iControl REST may lead to commands being executed with different privilege levels than expected.

Affected

95 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip_aam
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager12.1.0 – 12.1.2
f5big-ip_access_policy_manager>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_access_policy_manager>= 14.1.0 < 14.1.3.114.1.3.1
f5big-ip_access_policy_manager>= 15.1.0 < 15.1.215.1.2
f5big-ip_access_policy_manager>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_advanced_firewall_manager
f5big-ip_advanced_firewall_manager12.1.0 – 12.1.2
f5big-ip_advanced_firewall_manager>= 13.1.0 < 13.1.3.513.1.3.5
f5big-ip_advanced_firewall_manager>= 14.1.0 < 14.1.3.114.1.3.1
f5big-ip_advanced_firewall_manager>= 15.1.0 < 15.1.215.1.2
f5big-ip_advanced_firewall_manager>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_advanced_waf
f5big-ip_advanced_web_application_firewall>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_advanced_web_application_firewall>= 14.1.0 < 14.1.3.114.1.3.1
f5big-ip_advanced_web_application_firewall>= 15.1.0 < 15.1.215.1.2
f5big-ip_advanced_web_application_firewall>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics
f5big-ip_analytics12.1.0 – 12.1.2
f5big-ip_analytics>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_analytics>= 14.1.0 < 14.1.3.114.1.3.1
f5big-ip_analytics>= 15.1.0 < 15.1.215.1.2

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H