CVE-2019-6644
published 2019-09-04CVE-2019-6644: Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, and 12.1.0-12.1.4 BIG-IP will bind a debug…
PriorityP346critical9.4CVSS 3.1
AVNACLPRNUINSUCHIHAL
EPSS
1.40%
69.6th percentile
Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, and 12.1.0-12.1.4 BIG-IP will bind a debug nodejs process to all interfaces when invoked. This may expose the process to unauthorized users if the plugin is left in debug mode and the port is accessible.
Affected
65 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | 12.1.3 – 12.1.4 | — |
| f5 | big-ip_access_policy_manager | 13.0.0 – 13.1.2 | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | 12.1.3 – 12.1.4 | — |
| f5 | big-ip_advanced_firewall_manager | 13.0.0 – 13.1.2 | — |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 12.1.3 – 12.1.4 | — |
| f5 | big-ip_analytics | 13.0.0 – 13.1.2 | — |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | 12.1.3 – 12.1.4 | — |
| f5 | big-ip_application_acceleration_manager | 13.0.0 – 13.1.2 | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | 12.1.3 – 12.1.4 | — |
| f5 | big-ip_application_security_manager | 13.0.0 – 13.1.2 | — |
| f5 | big-ip_asm | — | — |
CVSS provenance
nvdv3.19.4CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2019-6644: Similar to the issue identified in CVE-2018-12120, on versions 14
vendor_f5·2019-09-04·CVSS 9.4
CVE-2019-6644 [HIGH] CVE-2019-6644: Similar to the issue identified in CVE-2018-12120, on versions 14
CVE-2019-6644: Similar to the issue identified in CVE-2018-12120, on versions 14
Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, and 12.1.0-12.1.4 BIG-IP will bind a debug nodejs process to all interfaces when invoked. This may expose the process to unauthorized users if the plugin is left in debug mode and the port is accessible.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Analytics, BIG-IP DNS, BIG-IP Edge Gateway, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP WebAccelerator
Affected Versions: 12.1.3 - 12.1.4; 13.0.0 - 13.1.2; 14.0.0; 14.1.0
F5 Advisory Articles: K75532331
F5 References: https://support.f5.com/csp/article/K75532331
GHSA
GHSA-jr9w-mmvc-9gp2: Similar to the issue identified in CVE-2018-12120, on versions 14
ghsa_unreviewed·2022-05-24·CVSS 8.1
CVE-2019-6644 [HIGH] GHSA-jr9w-mmvc-9gp2: Similar to the issue identified in CVE-2018-12120, on versions 14
Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, and 12.1.0-12.1.4 BIG-IP will bind a debug nodejs process to all interfaces when invoked. This may expose the process to unauthorized users if the plugin is left in debug mode and the port is accessible.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-09-04
Published