HIGH · 7.8

CVE-2012-1493

F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before...

Vulnerability Description

F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:C/I:N/A:N
Confidentiality
COMPLETE
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
F5Big-Ip Application Security Manager9.2.0
F5Big-Ip Global Traffic ManagerAll versions
F5Big-Ip Local Traffic ManagerAll versions
F5TmosAll versions
F5Big-Ip 1000All versions
F5Big-Ip 11000All versions
F5Big-Ip 11050All versions
F5Big-Ip 1500All versions
F5Big-Ip 1600All versions
F5Big-Ip 2400All versions
F5Big-Ip 3400All versions
F5Big-Ip 3410All versions
F5Big-Ip 3600All versions
F5Big-Ip 3900All versions
F5Big-Ip 4100All versions
F5Big-Ip 5100All versions
F5Big-Ip 5110All versions
F5Big-Ip 6400All versions
F5Big-Ip 6800All versions
F5Big-Ip 6900All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-1493?

CVE-2012-1493 is a vulnerability with a CVSS score of 7.8 (HIGH). F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before...

How severe is CVE-2012-1493?

CVE-2012-1493 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-1493?

Check the references section above for vendor advisories and patch information. Affected products include: F5 Big-Ip Application Security Manager, F5 Big-Ip Global Traffic Manager, F5 Big-Ip Local Traffic Manager, F5 Tmos, F5 Big-Ip 1000.