CVE-2019-6625
published 2019-07-03CVE-2019-6625: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a reflected cross-site scripting (XSS) vulnerability exists in…
PriorityP425medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
0.83%
53.9th percentile
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI) also known as the BIG-IP Configuration utility.
Affected
83 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | — | — |
| f5 | big-ip | — | — |
| f5 | big-ip | — | — |
| f5 | big-ip | — | — |
| f5 | big-ip | — | — |
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | 11.5.1 – 11.6.3 | — |
| f5 | big-ip_access_policy_manager | >= 12.1.0 < 12.1.4.1 | 12.1.4.1 |
| f5 | big-ip_access_policy_manager | >= 13.0.0 < 13.1.1.5 | 13.1.1.5 |
| f5 | big-ip_access_policy_manager | >= 14.0.0 < 14.0.0.5 | 14.0.0.5 |
| f5 | big-ip_access_policy_manager | >= 14.1.0 < 14.1.0.6 | 14.1.0.6 |
| f5 | big-ip_advanced_firewall_manager | 11.5.1 – 11.6.3 | — |
| f5 | big-ip_advanced_firewall_manager | >= 12.1.0 < 12.1.4.1 | 12.1.4.1 |
| f5 | big-ip_advanced_firewall_manager | >= 13.0.0 < 13.1.1.5 | 13.1.1.5 |
| f5 | big-ip_advanced_firewall_manager | >= 14.0.0 < 14.0.0.5 | 14.0.0.5 |
| f5 | big-ip_advanced_firewall_manager | >= 14.1.0 < 14.1.0.6 | 14.1.0.6 |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 11.5.1 – 11.6.3 | — |
| f5 | big-ip_analytics | >= 12.1.0 < 12.1.4.1 | 12.1.4.1 |
| f5 | big-ip_analytics | >= 13.0.0 < 13.1.1.5 | 13.1.1.5 |
| f5 | big-ip_analytics | >= 14.0.0 < 14.0.0.5 | 14.0.0.5 |
| f5 | big-ip_analytics | >= 14.1.0 < 14.1.0.6 | 14.1.0.6 |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_application_acceleration_manager | 11.5.1 – 11.6.3 | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2019-6625: On BIG-IP 14
vendor_f5·2019-07-03·CVSS 6.1
CVE-2019-6625 [MEDIUM] CWE-79 CVE-2019-6625: On BIG-IP 14
CVE-2019-6625: On BIG-IP 14
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI) also known as the BIG-IP Configuration utility.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Analytics, BIG-IP DNS, BIG-IP Edge Gateway, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP WebAccelerator, BIG-IP WebSafe
Affected Versions: 11.5.1 - 11.6.3; 12.1.0 - 12.1.4.1; 13.0.0 - 13.1.1.5; 14.0.0 - 14.0.0.5; 14.1.0 - 14.1.0.6
F5 Advisory Articles: K79902360
F5 References: https://support.f5.com/csp/article/K79902360
GHSA
GHSA-hphh-8v38-vfj6: On BIG-IP 14
ghsa_unreviewed·2022-05-24
CVE-2019-6625 [MEDIUM] CWE-79 GHSA-hphh-8v38-vfj6: On BIG-IP 14
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI) also known as the BIG-IP Configuration utility.
Project0
The More You Know, The More You Know You Don’t Know - Project Zero
project_zero·2022-04-01
CVE-2016-4654 The More You Know, The More You Know You Don’t Know - Project Zero
A Year in Review of 0-days Used In-the-Wild in 2021
Posted by Maddie Stone, Google Project Zero
This is our third annual year in review of 0-days exploited in-the-wild [2020, 2019]. Each year we’ve looked back at all of the detected and disclosed in-the-wild 0-days as a group and synthesized what we think the trends and takeaways are. The goal of this report is not to detail each individual exploit, but instead to analyze the exploits from the year as a group, looking for trends, gaps, lessons learned, successes, etc. If you’re interested in the analysis of individual exploits, please check out our root cause analysis repository.
We perform and share this analysis in order to make 0-day hard. We want it to be more costly, more resource intensive, and overall more difficult for
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-07-03
Published