CVE-2019-6618
published 2019-05-03CVE-2019-6618: On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, users with the Resource Administrator role can modify sensitive…
PriorityP425medium4.9CVSS 3.0
AVNACLPRHUINSUCNIHAN
EPSS
0.89%
55.5th percentile
On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, users with the Resource Administrator role can modify sensitive portions of the filesystem if provided Advanced Shell Access, such as editing /etc/passwd. This allows modifications to user objects and is contrary to our definition for the Resource Administrator (RA) role restrictions.
Affected
78 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | 11.5.2 – 11.5.8 | — |
| f5 | big-ip_access_policy_manager | 11.6.1 – 11.6.3.4 | — |
| f5 | big-ip_access_policy_manager | 12.1.0 – 12.1.4 | — |
| f5 | big-ip_access_policy_manager | 13.0.0 – 13.1.1.4 | — |
| f5 | big-ip_access_policy_manager | 14.0.0 – 14.1.0.1 | — |
| f5 | big-ip_advanced_firewall_manager | 11.5.2 – 11.5.8 | — |
| f5 | big-ip_advanced_firewall_manager | 11.6.1 – 11.6.3.4 | — |
| f5 | big-ip_advanced_firewall_manager | 12.1.0 – 12.1.4 | — |
| f5 | big-ip_advanced_firewall_manager | 13.0.0 – 13.1.1.4 | — |
| f5 | big-ip_advanced_firewall_manager | 14.0.0 – 14.1.0.1 | — |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 11.5.2 – 11.5.8 | — |
| f5 | big-ip_analytics | 11.6.1 – 11.6.3.4 | — |
| f5 | big-ip_analytics | 12.1.0 – 12.1.4 | — |
| f5 | big-ip_analytics | 13.0.0 – 13.1.1.4 | — |
| f5 | big-ip_analytics | 14.0.0 – 14.1.0.1 | — |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_application_acceleration_manager | 11.5.2 – 11.5.8 | — |
| f5 | big-ip_application_acceleration_manager | 11.6.1 – 11.6.3.4 | — |
| f5 | big-ip_application_acceleration_manager | 12.1.0 – 12.1.4 | — |
| f5 | big-ip_application_acceleration_manager | 13.0.0 – 13.1.1.4 | — |
| f5 | big-ip_application_acceleration_manager | 14.0.0 – 14.1.0.1 | — |
| f5 | big-ip_application_security_manager | 11.5.2 – 11.5.8 | — |
CVSS provenance
nvdv3.04.9MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2019-6618: On BIG-IP 14
vendor_f5·2019-05-03·CVSS 4.9
CVE-2019-6618 [MEDIUM] CVE-2019-6618: On BIG-IP 14
CVE-2019-6618: On BIG-IP 14
On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, users with the Resource Administrator role can modify sensitive portions of the filesystem if provided Advanced Shell Access, such as editing /etc/passwd. This allows modifications to user objects and is contrary to our definition for the Resource Administrator (RA) role restrictions.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Analytics, BIG-IP DNS, BIG-IP Edge Gateway, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP WebAccelerator
Affected Versions: 11.5.2 - 11.5.8; 11.6.1 - 11.6.3.4; 12.1.0 - 12.1.4; 13.0.0 - 13.1.1.4; 14.0.0 - 14.1.0.1
F5 Advisory Articles: K07702240
F5 References: https://support.f5.co
GHSA
GHSA-jqpq-g57p-mp22: On BIG-IP 14
ghsa_unreviewed·2022-05-24
CVE-2019-6618 [MEDIUM] GHSA-jqpq-g57p-mp22: On BIG-IP 14
On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, users with the Resource Administrator role can modify sensitive portions of the filesystem if provided Advanced Shell Access, such as editing /etc/passwd. This allows modifications to user objects and is contrary to our definition for the Resource Administrator (RA) role restrictions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-05-03
Published