CVE-2019-6687
published 2019-12-23CVE-2019-6687: On versions 15.0.0-15.0.1.1, the BIG-IP ASM Cloud Security Services profile uses a built-in verification mechanism that fails to properly authenticate the…
PriorityP337high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.48%
38.5th percentile
On versions 15.0.0-15.0.1.1, the BIG-IP ASM Cloud Security Services profile uses a built-in verification mechanism that fails to properly authenticate the X.509 certificate of remote endpoints.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_application_security_manager | >= 15.0.0 < 15.1.0 | 15.1.0 |
| f5 | big-ip_asm | — | — |
| f5 | big-ip_asm | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2019-6687: On versions 15
vendor_f5·2019-12-23·CVSS 7.4
CVE-2019-6687 [HIGH] CWE-295 CVE-2019-6687: On versions 15
CVE-2019-6687: On versions 15
On versions 15.0.0-15.0.1.1, the BIG-IP ASM Cloud Security Services profile uses a built-in verification mechanism that fails to properly authenticate the X.509 certificate of remote endpoints.
Affected Products: BIG-IP ASM
Affected Versions: 15.0.0 - 15.1.0
F5 Advisory Articles: K59957337
F5 References: https://support.f5.com/csp/article/K59957337
GHSA
GHSA-33c8-c6vf-6wgg: On versions 15
ghsa_unreviewed·2022-05-24
CVE-2019-6687 [MEDIUM] GHSA-33c8-c6vf-6wgg: On versions 15
On versions 15.0.0-15.0.1.1, the BIG-IP ASM Cloud Security Services profile uses a built-in verification mechanism that fails to properly authenticate the X.509 certificate of remote endpoints.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-12-23
Published