Added |
CVSS V3.1 |
|
NIST AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
|
Added |
CVSS V2 |
|
NIST (AV:N/AC:M/Au:S/C:P/I:P/A:P)
|
Added |
CWE |
|
NIST CWE-20
|
Added |
CPE Configuration |
|
OR
*cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* versions from (including) 11.6.1 up to (including) 11.6.5.2
*cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* versions from (including) 11.6.1 up to (including) 11.6.5.2
*cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* versions from (including) 11.6.1 up to (including) 11.6.5.2
*cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* versions from (including) 11.6.1 up to (including) 11.6.5.2
*cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* versions from (including) 11.6.1 up to (including) 11.6.5.2
*cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* versions from (including) 11.6.1 up to (including) 11.6.5.2
*cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* versions from (including) 11.6.1 up to (including) 11.6.5.2
*cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* versions from (including) 11.6.1 up to (including) 11.6.5.2
*cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* versions from (including) 11.6.1 up to (including) 11.6.5.2
*cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* versions from (including) 11.6.1 up to (including) 11.6.5.2
*cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* versions from (including) 11.6.1 up to (including) 11.6.5.2
|
Changed |
Reference Type |
https://support.f5.com/csp/article/K07051153 No Types Assigned
|
https://support.f5.com/csp/article/K07051153 Vendor Advisory
|
Changed |
Reference Type |
https://www.kb.cert.org/vuls/id/290915 No Types Assigned
|
https://www.kb.cert.org/vuls/id/290915 Third Party Advisory
|
Added |
CVSS V2 Metadata |
|
Victim must voluntarily interact with attack mechanism
|