CVE-2019-6642 Information

Description

In BIG-IP 15.0.0 14.0.0-14.1.0.5 13.0.0-13.1.1.5 12.1.0-12.1.4.2 and 11.5.2-11.6.4 BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0 iWorkflow 2.3.0 and Enterprise Manager 3.1.1 authenticated users with the ability to upload files (via scp for example) can escalate their privileges to allow root shell access from within the TMOS Shell (tmsh) interface. The tmsh interface allows users to execute a secondary program via tools like sftp or scp.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

https://support.f5.com/csp/article/K40378764 https://support.f5.com/csp/article/K40378764?utm_source=f5support&utm_medium=RSS

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.8

Share on: