Unknown
CVE-2019-6675
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2019-6675
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multiple servers are exposed to a vulnerability which allows an authentication bypass. This can result in a complete compromise of the system. This issue only impacts specific engineering hotfixes using the aforementioned authentication configuration. NOTE: This vulnerability does not affect any of the BIG-IP major, minor or maintenance releases you obtained from downloads.f5.com. The affected Engineering Hotfix builds are as follows: Hotfix-BIGIP-14.1.0.3.0.79.6-ENG.iso, Hotfix-BIGIP-14.1.0.3.0.97.6-ENG.iso, Hotfix-BIGIP-14.1.0.3.0.99.6-ENG.iso, Hotfix-BIGIP-14.1.0.5.0.15.5-ENG.iso, Hotfix-BIGIP-14.1.0.5.0.36.5-ENG.iso, Hotfix-BIGIP-14.1.0.5.0.40.5-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.11.9-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.14.9-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.68.9-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.70.9-ENG.iso, Hotfix-BIGIP-14.1.2.0.11.37-ENG.iso, Hotfix-BIGIP-14.1.2.0.18.37-ENG.iso, Hotfix-BIGIP-14.1.2.0.32.37-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.46.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.14.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.16.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.34.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.97.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.99.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.105.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.111.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.115.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.122.4-ENG.iso, Hotfix-BIGIP-15.0.1.0.33.11-ENG.iso, Hotfix-BIGIP-15.0.1.0.48.11-ENG.iso
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- big-ip access policy manager,
- big-ip access policy manager 14.1.0.3.0.79.6-eng hotfix,
- big-ip access policy manager 14.1.0.3.0.97.6-eng hotfix,
- big-ip access policy manager 14.1.0.3.0.99.6-eng hotfix,
- big-ip access policy manager 14.1.0.5.0.15.5-eng hotfix,
- big-ip access policy manager 14.1.0.5.0.36.5-eng hotfix,
- big-ip access policy manager 14.1.0.5.0.40.5-eng hotfix,
- big-ip access policy manager 14.1.0.6.0.11.9-eng hotfix,
- big-ip access policy manager 14.1.0.6.0.14.9-eng hotfix,
- big-ip access policy manager 14.1.0.6.0.68.9-eng hotfix,
- big-ip access policy manager 14.1.0.6.0.70.9-eng hotfix,
- big-ip access policy manager 14.1.2.0.11.37-eng hotfix,
- big-ip access policy manager 14.1.2.0.18.37-eng hotfix,
- big-ip access policy manager 14.1.2.0.32.37-eng hotfix,
- big-ip access policy manager 14.1.2.1.0.105.4-eng hotfix,
- big-ip access policy manager 14.1.2.1.0.111.4-eng hotfix,
- big-ip access policy manager 14.1.2.1.0.115.4-eng hotfix,
- big-ip access policy manager 14.1.2.1.0.122.4-eng hotfix,
- big-ip access policy manager 14.1.2.1.0.14.4-eng hotfix,
- big-ip access policy manager 14.1.2.1.0.16.4-eng hotfix,
- big-ip access policy manager 14.1.2.1.0.34.4-eng hotfix,
- big-ip access policy manager 14.1.2.1.0.46.4-eng hotfix,
- big-ip access policy manager 14.1.2.1.0.97.4-eng hotfix,
- big-ip access policy manager 14.1.2.1.0.99.4-eng hotfix,
- big-ip advanced firewall manager,
- big-ip advanced firewall manager 14.1.0.3.0.79.6-eng hotfix,
- big-ip advanced firewall manager 14.1.0.3.0.97.6-eng hotfix,
- big-ip advanced firewall manager 14.1.0.3.0.99.6-eng hotfix,
- big-ip advanced firewall manager 14.1.0.5.0.15.5-eng hotfix,
- big-ip advanced firewall manager 14.1.0.5.0.36.5-eng hotfix,
- big-ip advanced firewall manager 14.1.0.5.0.40.5-eng hotfix,
- big-ip advanced firewall manager 14.1.0.6.0.11.9-eng hotfix,
- big-ip advanced firewall manager 14.1.0.6.0.14.9-eng hotfix,
- big-ip advanced firewall manager 14.1.0.6.0.68.9-eng hotfix,
- big-ip advanced firewall manager 14.1.0.6.0.70.9-eng hotfix,
- big-ip advanced firewall manager 14.1.2.0.11.37-eng hotfix,
- big-ip advanced firewall manager 14.1.2.0.18.37-eng hotfix,
- big-ip advanced firewall manager 14.1.2.0.32.37-eng hotfix,
- big-ip advanced firewall manager 14.1.2.1.0.105.4-eng hotfix,
- big-ip advanced firewall manager 14.1.2.1.0.111.4-eng hotfix,
- big-ip advanced firewall manager 14.1.2.1.0.115.4-eng hotfix,
- big-ip advanced firewall manager 14.1.2.1.0.122.4-eng hotfix,
- big-ip advanced firewall manager 14.1.2.1.0.14.4-eng hotfix,
- big-ip advanced firewall manager 14.1.2.1.0.16.4-eng hotfix,
- big-ip advanced firewall manager 14.1.2.1.0.34.4-eng hotfix,
- big-ip advanced firewall manager 14.1.2.1.0.46.4-eng hotfix,
- big-ip advanced firewall manager 14.1.2.1.0.97.4-eng hotfix,
- big-ip advanced firewall manager 14.1.2.1.0.99.4-eng hotfix,
- big-ip analytics,
- big-ip analytics 14.1.0.3.0.79.6-eng hotfix,
- big-ip analytics 14.1.0.3.0.97.6-eng hotfix,
- big-ip analytics 14.1.0.3.0.99.6-eng hotfix,
- big-ip analytics 14.1.0.5.0.15.5-eng hotfix,
- big-ip analytics 14.1.0.5.0.36.5-eng hotfix,
- big-ip analytics 14.1.0.5.0.40.5-eng hotfix,
- big-ip analytics 14.1.0.6.0.11.9-eng hotfix,
- big-ip analytics 14.1.0.6.0.14.9-eng hotfix,
- big-ip analytics 14.1.0.6.0.68.9-eng hotfix,
- big-ip analytics 14.1.0.6.0.70.9-eng hotfix,
- big-ip analytics 14.1.2.0.11.37-eng hotfix,
- big-ip analytics 14.1.2.0.18.37-eng hotfix,
- big-ip analytics 14.1.2.0.32.37-eng hotfix,
- big-ip analytics 14.1.2.1.0.105.4-eng hotfix,
- big-ip analytics 14.1.2.1.0.111.4-eng hotfix,
- big-ip analytics 14.1.2.1.0.115.4-eng hotfix,
- big-ip analytics 14.1.2.1.0.122.4-eng hotfix,
- big-ip analytics 14.1.2.1.0.14.4-eng hotfix,
- big-ip analytics 14.1.2.1.0.16.4-eng hotfix,
- big-ip analytics 14.1.2.1.0.34.4-eng hotfix,
- big-ip analytics 14.1.2.1.0.46.4-eng hotfix,
- big-ip analytics 14.1.2.1.0.97.4-eng hotfix,
- big-ip analytics 14.1.2.1.0.99.4-eng hotfix,
- big-ip application acceleration manager,
- big-ip application acceleration manager 14.1.0.3.0.79.6-eng hotfix,
- big-ip application acceleration manager 14.1.0.3.0.97.6-eng hotfix,
- big-ip application acceleration manager 14.1.0.3.0.99.6-eng hotfix,
- big-ip application acceleration manager 14.1.0.5.0.15.5-eng hotfix,
- big-ip application acceleration manager 14.1.0.5.0.36.5-eng hotfix,
- big-ip application acceleration manager 14.1.0.5.0.40.5-eng hotfix,
- big-ip application acceleration manager 14.1.0.6.0.11.9-eng hotfix,
- big-ip application acceleration manager 14.1.0.6.0.14.9-eng hotfix,
- big-ip application acceleration manager 14.1.0.6.0.68.9-eng hotfix,
- big-ip application acceleration manager 14.1.0.6.0.70.9-eng hotfix,
- big-ip application acceleration manager 14.1.2.0.11.37-eng hotfix,
- big-ip application acceleration manager 14.1.2.0.18.37-eng hotfix,
- big-ip application acceleration manager 14.1.2.0.32.37-eng hotfix,
- big-ip application acceleration manager 14.1.2.1.0.105.4-eng hotfix,
- big-ip application acceleration manager 14.1.2.1.0.111.4-eng hotfix,
- big-ip application acceleration manager 14.1.2.1.0.115.4-eng hotfix,
- big-ip application acceleration manager 14.1.2.1.0.122.4-eng hotfix,
- big-ip application acceleration manager 14.1.2.1.0.14.4-eng hotfix,
- big-ip application acceleration manager 14.1.2.1.0.16.4-eng hotfix,
- big-ip application acceleration manager 14.1.2.1.0.34.4-eng hotfix,
- big-ip application acceleration manager 14.1.2.1.0.46.4-eng hotfix,
- big-ip application acceleration manager 14.1.2.1.0.97.4-eng hotfix,
- big-ip application acceleration manager 14.1.2.1.0.99.4-eng hotfix,
- big-ip application security manager,
- big-ip application security manager 14.1.0.3.0.79.6-eng hotfix,
- big-ip application security manager 14.1.0.3.0.97.6-eng hotfix,
- big-ip application security manager 14.1.0.3.0.99.6-eng hotfix,
- big-ip application security manager 14.1.0.5.0.15.5-eng hotfix,
- big-ip application security manager 14.1.0.5.0.36.5-eng hotfix,
- big-ip application security manager 14.1.0.5.0.40.5-eng hotfix,
- big-ip application security manager 14.1.0.6.0.11.9-eng hotfix,
- big-ip application security manager 14.1.0.6.0.14.9-eng hotfix,
- big-ip application security manager 14.1.0.6.0.68.9-eng hotfix,
- big-ip application security manager 14.1.0.6.0.70.9-eng hotfix,
- big-ip application security manager 14.1.2.0.11.37-eng hotfix,
- big-ip application security manager 14.1.2.0.18.37-eng hotfix,
- big-ip application security manager 14.1.2.0.32.37-eng hotfix,
- big-ip application security manager 14.1.2.1.0.105.4-eng hotfix,
- big-ip application security manager 14.1.2.1.0.111.4-eng hotfix,
- big-ip application security manager 14.1.2.1.0.115.4-eng hotfix,
- big-ip application security manager 14.1.2.1.0.122.4-eng hotfix,
- big-ip application security manager 14.1.2.1.0.14.4-eng hotfix,
- big-ip application security manager 14.1.2.1.0.16.4-eng hotfix,
- big-ip application security manager 14.1.2.1.0.34.4-eng hotfix,
- big-ip application security manager 14.1.2.1.0.46.4-eng hotfix,
- big-ip application security manager 14.1.2.1.0.97.4-eng hotfix,
- big-ip application security manager 14.1.2.1.0.99.4-eng hotfix,
- big-ip domain name system,
- big-ip domain name system 14.1.0.3.0.79.6-eng hotfix,
- big-ip domain name system 14.1.0.3.0.97.6-eng hotfix,
- big-ip domain name system 14.1.0.3.0.99.6-eng hotfix,
- big-ip domain name system 14.1.0.5.0.15.5-eng hotfix,
- big-ip domain name system 14.1.0.5.0.36.5-eng hotfix,
- big-ip domain name system 14.1.0.5.0.40.5-eng hotfix,
- big-ip domain name system 14.1.0.6.0.11.9-eng hotfix,
- big-ip domain name system 14.1.0.6.0.14.9-eng hotfix,
- big-ip domain name system 14.1.0.6.0.68.9-eng hotfix,
- big-ip domain name system 14.1.0.6.0.70.9-eng hotfix,
- big-ip domain name system 14.1.2.0.11.37-eng hotfix,
- big-ip domain name system 14.1.2.0.18.37-eng hotfix,
- big-ip domain name system 14.1.2.0.32.37-eng hotfix,
- big-ip domain name system 14.1.2.1.0.105.4-eng hotfix,
- big-ip domain name system 14.1.2.1.0.111.4-eng hotfix,
- big-ip domain name system 14.1.2.1.0.115.4-eng hotfix,
- big-ip domain name system 14.1.2.1.0.122.4-eng hotfix,
- big-ip domain name system 14.1.2.1.0.14.4-eng hotfix,
- big-ip domain name system 14.1.2.1.0.16.4-eng hotfix,
- big-ip domain name system 14.1.2.1.0.34.4-eng hotfix,
- big-ip domain name system 14.1.2.1.0.46.4-eng hotfix,
- big-ip domain name system 14.1.2.1.0.97.4-eng hotfix,
- big-ip domain name system 14.1.2.1.0.99.4-eng hotfix,
- big-ip fraud protection service,
- big-ip fraud protection service 14.1.0.3.0.79.6-eng hotfix,
- big-ip fraud protection service 14.1.0.3.0.97.6-eng hotfix,
- big-ip fraud protection service 14.1.0.3.0.99.6-eng hotfix,
- big-ip fraud protection service 14.1.0.5.0.15.5-eng hotfix,
- big-ip fraud protection service 14.1.0.5.0.36.5-eng hotfix,
- big-ip fraud protection service 14.1.0.5.0.40.5-eng hotfix,
- big-ip fraud protection service 14.1.0.6.0.11.9-eng hotfix,
- big-ip fraud protection service 14.1.0.6.0.14.9-eng hotfix,
- big-ip fraud protection service 14.1.0.6.0.68.9-eng hotfix,
- big-ip fraud protection service 14.1.0.6.0.70.9-eng hotfix,
- big-ip fraud protection service 14.1.2.0.11.37-eng hotfix,
- big-ip fraud protection service 14.1.2.0.18.37-eng hotfix,
- big-ip fraud protection service 14.1.2.0.32.37-eng hotfix,
- big-ip fraud protection service 14.1.2.1.0.105.4-eng hotfix,
- big-ip fraud protection service 14.1.2.1.0.111.4-eng hotfix,
- big-ip fraud protection service 14.1.2.1.0.115.4-eng hotfix,
- big-ip fraud protection service 14.1.2.1.0.122.4-eng hotfix,
- big-ip fraud protection service 14.1.2.1.0.14.4-eng hotfix,
- big-ip fraud protection service 14.1.2.1.0.16.4-eng hotfix,
- big-ip fraud protection service 14.1.2.1.0.34.4-eng hotfix,
- big-ip fraud protection service 14.1.2.1.0.46.4-eng hotfix,
- big-ip fraud protection service 14.1.2.1.0.97.4-eng hotfix,
- big-ip fraud protection service 14.1.2.1.0.99.4-eng hotfix,
- big-ip global traffic manager,
- big-ip global traffic manager 14.1.0.3.0.79.6-eng hotfix,
- big-ip global traffic manager 14.1.0.3.0.97.6-eng hotfix,
- big-ip global traffic manager 14.1.0.3.0.99.6-eng hotfix,
- big-ip global traffic manager 14.1.0.5.0.15.5-eng hotfix,
- big-ip global traffic manager 14.1.0.5.0.36.5-eng hotfix,
- big-ip global traffic manager 14.1.0.5.0.40.5-eng hotfix,
- big-ip global traffic manager 14.1.0.6.0.11.9-eng hotfix,
- big-ip global traffic manager 14.1.0.6.0.14.9-eng hotfix,
- big-ip global traffic manager 14.1.0.6.0.68.9-eng hotfix,
- big-ip global traffic manager 14.1.0.6.0.70.9-eng hotfix,
- big-ip global traffic manager 14.1.2.0.11.37-eng hotfix,
- big-ip global traffic manager 14.1.2.0.18.37-eng hotfix,
- big-ip global traffic manager 14.1.2.0.32.37-eng hotfix,
- big-ip global traffic manager 14.1.2.1.0.105.4-eng hotfix,
- big-ip global traffic manager 14.1.2.1.0.111.4-eng hotfix,
- big-ip global traffic manager 14.1.2.1.0.115.4-eng hotfix,
- big-ip global traffic manager 14.1.2.1.0.122.4-eng hotfix,
- big-ip global traffic manager 14.1.2.1.0.14.4-eng hotfix,
- big-ip global traffic manager 14.1.2.1.0.16.4-eng hotfix,
- big-ip global traffic manager 14.1.2.1.0.34.4-eng hotfix,
- big-ip global traffic manager 14.1.2.1.0.46.4-eng hotfix,
- big-ip global traffic manager 14.1.2.1.0.97.4-eng hotfix,
- big-ip global traffic manager 14.1.2.1.0.99.4-eng hotfix,
- big-ip link controller,
- big-ip link controller 14.1.0.3.0.79.6-eng hotfix,
- big-ip link controller 14.1.0.3.0.97.6-eng hotfix,
- big-ip link controller 14.1.0.3.0.99.6-eng hotfix,
- big-ip link controller 14.1.0.5.0.15.5-eng hotfix,
- big-ip link controller 14.1.0.5.0.36.5-eng hotfix,
- big-ip link controller 14.1.0.5.0.40.5-eng hotfix,
- big-ip link controller 14.1.0.6.0.11.9-eng hotfix,
- big-ip link controller 14.1.0.6.0.14.9-eng hotfix,
- big-ip link controller 14.1.0.6.0.68.9-eng hotfix,
- big-ip link controller 14.1.0.6.0.70.9-eng hotfix,
- big-ip link controller 14.1.2.0.11.37-eng hotfix,
- big-ip link controller 14.1.2.0.18.37-eng hotfix,
- big-ip link controller 14.1.2.0.32.37-eng hotfix,
- big-ip link controller 14.1.2.1.0.105.4-eng hotfix,
- big-ip link controller 14.1.2.1.0.111.4-eng hotfix,
- big-ip link controller 14.1.2.1.0.115.4-eng hotfix,
- big-ip link controller 14.1.2.1.0.122.4-eng hotfix,
- big-ip link controller 14.1.2.1.0.14.4-eng hotfix,
- big-ip link controller 14.1.2.1.0.16.4-eng hotfix,
- big-ip link controller 14.1.2.1.0.34.4-eng hotfix,
- big-ip link controller 14.1.2.1.0.46.4-eng hotfix,
- big-ip link controller 14.1.2.1.0.97.4-eng hotfix,
- big-ip link controller 14.1.2.1.0.99.4-eng hotfix,
- big-ip local traffic manager,
- big-ip local traffic manager 14.1.0.3.0.79.6-eng hotfix,
- big-ip local traffic manager 14.1.0.3.0.97.6-eng hotfix,
- big-ip local traffic manager 14.1.0.3.0.99.6-eng hotfix,
- big-ip local traffic manager 14.1.0.5.0.15.5-eng hotfix,
- big-ip local traffic manager 14.1.0.5.0.36.5-eng hotfix,
- big-ip local traffic manager 14.1.0.5.0.40.5-eng hotfix,
- big-ip local traffic manager 14.1.0.6.0.11.9-eng hotfix,
- big-ip local traffic manager 14.1.0.6.0.14.9-eng hotfix,
- big-ip local traffic manager 14.1.0.6.0.68.9-eng hotfix,
- big-ip local traffic manager 14.1.0.6.0.70.9-eng hotfix,
- big-ip local traffic manager 14.1.2.0.11.37-eng hotfix,
- big-ip local traffic manager 14.1.2.0.18.37-eng hotfix,
- big-ip local traffic manager 14.1.2.0.32.37-eng hotfix,
- big-ip local traffic manager 14.1.2.1.0.105.4-eng hotfix,
- big-ip local traffic manager 14.1.2.1.0.111.4-eng hotfix,
- big-ip local traffic manager 14.1.2.1.0.115.4-eng hotfix,
- big-ip local traffic manager 14.1.2.1.0.122.4-eng hotfix,
- big-ip local traffic manager 14.1.2.1.0.14.4-eng hotfix,
- big-ip local traffic manager 14.1.2.1.0.16.4-eng hotfix,
- big-ip local traffic manager 14.1.2.1.0.34.4-eng hotfix,
- big-ip local traffic manager 14.1.2.1.0.46.4-eng hotfix,
- big-ip local traffic manager 14.1.2.1.0.97.4-eng hotfix,
- big-ip local traffic manager 14.1.2.1.0.99.4-eng hotfix,
- big-ip policy enforcement manager,
- big-ip policy enforcement manager 14.1.0.3.0.79.6-eng hotfix,
- big-ip policy enforcement manager 14.1.0.3.0.97.6-eng hotfix,
- big-ip policy enforcement manager 14.1.0.3.0.99.6-eng hotfix,
- big-ip policy enforcement manager 14.1.0.5.0.15.5-eng hotfix,
- big-ip policy enforcement manager 14.1.0.5.0.36.5-eng hotfix,
- big-ip policy enforcement manager 14.1.0.5.0.40.5-eng hotfix,
- big-ip policy enforcement manager 14.1.0.6.0.11.9-eng hotfix,
- big-ip policy enforcement manager 14.1.0.6.0.14.9-eng hotfix,
- big-ip policy enforcement manager 14.1.0.6.0.68.9-eng hotfix,
- big-ip policy enforcement manager 14.1.0.6.0.70.9-eng hotfix,
- big-ip policy enforcement manager 14.1.2.0.11.37-eng hotfix,
- big-ip policy enforcement manager 14.1.2.0.18.37-eng hotfix,
- big-ip policy enforcement manager 14.1.2.0.32.37-eng hotfix,
- big-ip policy enforcement manager 14.1.2.1.0.105.4-eng hotfix,
- big-ip policy enforcement manager 14.1.2.1.0.111.4-eng hotfix,
- big-ip policy enforcement manager 14.1.2.1.0.115.4-eng hotfix,
- big-ip policy enforcement manager 14.1.2.1.0.122.4-eng hotfix,
- big-ip policy enforcement manager 14.1.2.1.0.14.4-eng hotfix,
- big-ip policy enforcement manager 14.1.2.1.0.16.4-eng hotfix,
- big-ip policy enforcement manager 14.1.2.1.0.34.4-eng hotfix,
- big-ip policy enforcement manager 14.1.2.1.0.46.4-eng hotfix,
- big-ip policy enforcement manager 14.1.2.1.0.97.4-eng hotfix,
- big-ip policy enforcement manager 14.1.2.1.0.99.4-eng hotfix
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: