CVE-2019-6601
published 2019-03-13CVE-2019-6601: In BIG-IP 13.0.0, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, the Application Acceleration Manager (AAM) wamd process used in processing of images and…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.32%
24.3th percentile
In BIG-IP 13.0.0, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, the Application Acceleration Manager (AAM) wamd process used in processing of images and PDFs fails to drop group permissions when executing helper scripts.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_aam | — | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | 11.2.1 – 11.5.8 | — |
| f5 | big-ip_application_acceleration_manager | 11.6.1 – 11.6.3 | — |
| f5 | big-ip_application_acceleration_manager | 12.1.0 – 12.1.3 | — |
| f5_networks_inc | big-ip | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2019-6601: In BIG-IP 13
vendor_f5·2019-03-13·CVSS 5.5
CVE-2019-6601 [MEDIUM] CWE-269 CVE-2019-6601: In BIG-IP 13
CVE-2019-6601: In BIG-IP 13
In BIG-IP 13.0.0, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, the Application Acceleration Manager (AAM) wamd process used in processing of images and PDFs fails to drop group permissions when executing helper scripts.
Affected Products: BIG-IP AAM
Affected Versions: 11.2.1 - 11.5.8; 11.6.1 - 11.6.3; 12.1.0 - 12.1.3; 13.0.0
F5 Advisory Articles: K25359902
F5 References: https://support.f5.com/csp/article/K25359902
GHSA
GHSA-frpm-gc6w-7xpf: In BIG-IP 13
ghsa_unreviewed·2022-05-13
CVE-2019-6601 [MEDIUM] CWE-269 GHSA-frpm-gc6w-7xpf: In BIG-IP 13
In BIG-IP 13.0.0, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, the Application Acceleration Manager (AAM) wamd process used in processing of images and PDFs fails to drop group permissions when executing helper scripts.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-03-13
Published