CVE-2019-6653Cross-site Scripting in F5 Big-iq Centralized Management

Severity
5.4MEDIUMNVD
EPSS
0.2%
top 56.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 25
Latest updateMay 24

Description

There is a Stored Cross Site Scripting vulnerability in the undisclosed page of a BIG-IQ 6.0.0-6.1.0 or 5.2.0-5.4.0 system. The attack can be stored by users granted the Device Manager and Administrator roles.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

NVDf5/big-iq_centralized_management5.2.05.4.0+1
CVEListV5f5/big-iq_centralized_management6.0.0-6.1.0, 5.2.0-5.4.0

🔴Vulnerability Details

2
GHSA
GHSA-hpc7-3xjf-jp7w: There is a Stored Cross Site Scripting vulnerability in the undisclosed page of a BIG-IQ 62022-05-24
CVEList
CVE-2019-6653: There is a Stored Cross Site Scripting vulnerability in the undisclosed page of a BIG-IQ 62019-09-25

📋Vendor Advisories

1
F5
CVE-2019-6653: There is a Stored Cross Site Scripting vulnerability in the undisclosed page of a BIG-IQ 62019-09-25
CVE-2019-6653 — Cross-site Scripting in F5 | cvebase