CVE-2017-6165 Information

Description

In F5 BIG-IP LTM AAM AFM Analytics APM ASM DNS GTM Link Controller PEM and WebSafe 11.5.1 HF6 through 11.5.4 HF4 11.6.0 through 11.6.1 HF1 and 12.0.0 through 12.1.2 on VIPRION platforms only the script which synchronizes SafeNet External Network HSM configuration elements between blades in a clustered deployment will log the HSM partition password in cleartext to the /var/log/ltm\ log file.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

http://www.securityfocus.com/bid/101543 http://www.securitytracker.com/id/1039638 https://support.f5.com/csp/article/K74759095

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

9.8

Share on: