cbcvebase.
CVE-2019-6688
published 2019-12-23

CVE-2019-6688: On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5 and BIG-IQ versions 6.0.0-6.1.0 and…

medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5 and BIG-IQ versions 6.0.0-6.1.0 and 5.2.0-5.4.0, a user is able to obtain the secret that was being used to encrypt a BIG-IP UCS backup file while sending SNMP query to the BIG-IP or BIG-IQ system, however the user can not access to the UCS files.

Affected

102 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip
f5big-ip
f5big-ip
f5big-ip
f5big-ip
f5big-ip
f5big-ip_aam
f5big-ip_access_policy_manager>= 11.5.2 < 11.6.5.111.6.5.1
f5big-ip_access_policy_manager12.1.0 – 12.1.5
f5big-ip_access_policy_manager>= 13.1.0 < 13.1.3.213.1.3.2
f5big-ip_access_policy_manager>= 14.0.0 < 14.0.1.114.0.1.1
f5big-ip_access_policy_manager>= 14.1.0 < 14.1.2.314.1.2.3
f5big-ip_access_policy_manager>= 15.0.0 < 15.1.015.1.0
f5big-ip_advanced_firewall_manager>= 11.5.2 < 11.6.5.111.6.5.1
f5big-ip_advanced_firewall_manager12.1.0 – 12.1.5
f5big-ip_advanced_firewall_manager>= 13.1.0 < 13.1.3.213.1.3.2
f5big-ip_advanced_firewall_manager>= 14.0.0 < 14.0.1.114.0.1.1
f5big-ip_advanced_firewall_manager>= 14.1.0 < 14.1.2.314.1.2.3
f5big-ip_advanced_firewall_manager>= 15.0.0 < 15.1.015.1.0
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics>= 11.5.2 < 11.6.5.111.6.5.1
f5big-ip_analytics12.1.0 – 12.1.5
f5big-ip_analytics>= 13.1.0 < 13.1.3.213.1.3.2
f5big-ip_analytics>= 14.0.0 < 14.0.1.114.0.1.1