CVE-2017-0305 Information
Feb 14, 2021
cve
Description
F5 SSL Intercept iApp version 1.5.0 - 1.5.7 is vulnerable to an unauthenticated remote attack that may allow modification of the BIG-IP system configuration extraction of sensitive system files and possible remote command execution on the system when deployed using the Explicit Proxy feature plus SNAT Auto Map option for egress traffic.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://support.f5.com/csp/article/K53244431
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: