HIGH · 7.4

CVE-2016-2084

F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, 11.6.0 before build 6...

Vulnerability Description

F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, 11.6.0 before build 6.204.442, and 12.0.0 before build 1.14.628; BIG-IP AAM 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, 11.6.0 before build 6.204.442, and 12.0.0 before build 1.14.628; BIG-IP DNS 12.0.0 before build 1.14.628; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.3.0; BIG-IP GTM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, and 11.6.0 before build 6.204.442; BIG-IP PSM 11.3.x and 11.4.x before 11.4.1 build 685-HF10; BIG-IQ Cloud, Device, and Security 4.2.0 through 4.5.0; and BIG-IQ ADC 4.5.0 do not properly regenerate certificates and keys when deploying cloud images in Amazon Web Services (AWS), Azure or Verizon cloud services environments, which allows attackers to obtain sensitive information or cause a denial of service (disruption) by leveraging a target instance configuration.

CVSS Score

7.4

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
F5Big-Iq Security4.2.0
F5Big-Ip Webaccelerator11.3.0
F5Big-Ip Application Security Manager11.3.0
F5Big-Ip Access Policy Manager11.3.0
F5Big-Ip Policy Enforcement Manager11.3.0
F5Big-Iq Cloud4.2.0
F5Big-Iq Application Delivery Controller4.5.0
F5Big-Ip Global Traffic Manager11.3.0
F5Big-Ip Local Traffic Manager11.3.0
F5Big-Iq Device4.2.0
F5Big-Ip Edge Gateway11.3.0
F5Big-Ip Application Acceleration Manager11.4.1
F5Big-Ip Wan Optimization Manager11.3.0
F5Big-Ip Advanced Firewall Manager11.3.0
F5Big-Ip Link Controller11.3.0
F5Big-Ip Protocol Security Module11.3.0
F5Big-Ip Analytics11.3.0
F5Big-Ip Domain Name System12.0.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-2084?

CVE-2016-2084 is a vulnerability with a CVSS score of 7.4 (HIGH). F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, 11.6.0 before build 6...

How severe is CVE-2016-2084?

CVE-2016-2084 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-2084?

Check the references section above for vendor advisories and patch information. Affected products include: F5 Big-Iq Security, F5 Big-Ip Webaccelerator, F5 Big-Ip Application Security Manager, F5 Big-Ip Access Policy Manager, F5 Big-Ip Policy Enforcement Manager.