CVE-2015-8611 Information

Description

BIG-IP LTM AAM AFM Analytics APM ASM DNS Link Controller and PEM 12.0.0 before HF1 on the 2000 4000 5000 7000 and 10000 platforms do not properly sync passwords with the Always-On Management (AOM) subsystem which might allow remote attackers to obtain login access to AOM via an (1) expired or (2) default password.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

http://www.securitytracker.com/id/1034629 https://support.f5.com/kb/en-us/solutions/public/k/05/sol05272632.html

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

9.8

Share on: