CVE-2019-6675
BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multiple servers are exposed to a vulnerability which allows an authentication bypass. This can result in a complete compromise of the system. This issue only impacts specific engineering hotfixes using the aforementioned authentication configuration. NOTE: This vulnerability does not affect any of the BIG-IP major, minor or maintenance releases you obtained from downloads.f5.com. The affected Engineering Hotfix builds are as follows: Hotfix-BIGIP-14.1.0.3.0.79.6-ENG.iso, Hotfix-BIGIP-14.1.0.3.0.97.6-ENG.iso, Hotfix-BIGIP-14.1.0.3.0.99.6-ENG.iso, Hotfix-BIGIP-14.1.0.5.0.15.5-ENG.iso, Hotfix-BIGIP-14.1.0.5.0.36.5-ENG.iso, Hotfix-BIGIP-14.1.0.5.0.40.5-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.11.9-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.14.9-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.68.9-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.70.9-ENG.iso, Hotfix-BIGIP-14.1.2.0.11.37-ENG.iso, Hotfix-BIGIP-14.1.2.0.18.37-ENG.iso, Hotfix-BIGIP-14.1.2.0.32.37-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.46.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.14.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.16.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.34.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.97.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.99.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.105.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.111.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.115.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.122.4-ENG.iso, Hotfix-BIGIP-15.0.1.0.33.11-ENG.iso, Hotfix-BIGIP-15.0.1.0.48.11-ENG.iso
EPSS 0.14% · 33.2th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | BIG-IP | Hotfix-BIGIP-14.1.0.3.0.79.6-ENG.iso, Hotfix-BIGIP-14.1.0.3.0.97.6-ENG.iso, Hotfix-BIGIP-14.1.0.3.0.99.6-ENG.iso, Hotfix-BIGIP-14.1.0.5.0.15.5-ENG.iso, Hotfix-BIGIP-14.1.0.5.0.36.5-ENG.iso, Hotfix-BIGIP-14.1.0.5.0.40.5-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.11.9-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.14.9-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.68.9-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.70.9-ENG.iso, Hotfix-BIGIP-14.1.2.0.11.37-ENG.iso, Hotfix-BIGIP-14.1.2.0.18.37-ENG.iso, Hotfix-BIGIP-14.1.2.0.32.37-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.46.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.14.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.16.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.34.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.97.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.99.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.105.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.111.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.115.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.122.4-ENG.iso, Hotfix-BIGIP-15.0.1.0.33.11-ENG.iso, Hotfix-BIGIP-15.0.1.0.48.11-ENG.iso |
| f5 | big-ip_application_security_manager | *, *, * |
| f5 | big-ip_domain_name_system | 15.0.1.0.33.11-eng_hotfix, 14.1.0.3.0.79.6-eng_hotfix, 14.1.0.3.0.97.6-eng_hotfix |
| f5 | big-ip_access_policy_manager | 14.1.0.5.0.15.5-eng_hotfix, 14.1.0.5.0.40.5-eng_hotfix, 14.1.0.6.0.11.9-eng_hotfix |
| f5 | big-ip_fraud_protection_service | *, *, * |
| f5 | big-ip_local_traffic_manager | 14.1.2.1.0.122.4-eng_hotfix, 15.0.1.0.33.11-eng_hotfix, 14.1.0.3.0.79.6-eng_hotfix |
| f5 | big-ip_policy_enforcement_manager | 15.0.1.0.33.11-eng_hotfix, 14.1.0.3.0.79.6-eng_hotfix, 14.1.0.3.0.97.6-eng_hotfix |
| f5 | big-ip_global_traffic_manager | 14.1.0.5.0.40.5-eng_hotfix, 15.0.1.0.33.11-eng_hotfix, 14.1.0.3.0.79.6-eng_hotfix |
| f5 | big-ip_application_acceleration_manager | *, *, * |
| f5 | big-ip_analytics | *, 14.1.0.3.0.97.6-eng_hotfix, 14.1.0.3.0.99.6-eng_hotfix |
| f5 | big-ip_link_controller | *, 14.1.0.3.0.79.6-eng_hotfix, 14.1.0.3.0.97.6-eng_hotfix |
| f5 | big-ip_advanced_firewall_manager | *, *, 14.1.2.1.0.122.4-eng_hotfix |
Exploit Intelligence
Timeline
- Nov 26, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://support.f5.com/csp/article/K05765031 advisory
- https://support.f5.com/csp/article/K39225055 advisory
- https://support.f5.com/csp/article/K63025104 advisory
- https://support.f5.com/csp/article/K49827114 advisory
- https://support.f5.com/csp/article/K81557381 advisory
- https://support.f5.com/csp/article/K21135478 advisory
- https://support.f5.com/csp/article/K11447758 advisory
- https://support.f5.com/csp/article/K23860356 advisory
- https://support.f5.com/csp/article/K82781208 advisory
- https://support.f5.com/csp/article/K55655944 advisory
- https://support.f5.com/csp/article/K14703097 advisory
- https://support.f5.com/csp/article/K92411323 advisory
- https://support.f5.com/csp/article/K55655944?utm_source=f5support&%3Butm_medium=RSS url
- https://nvd.nist.gov/vuln/detail/CVE-2019-6675 advisory
- https://support.f5.com/csp/article/K55655944?utm_source=f5support&utm_medium=RSS url