Vulnerability Description
A local user on F5 BIG-IQ Centralized Management 5.1.0-5.2.0 with the Access Manager role has privileges to change the passwords of other users on the system, including the local admin account password.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Iq Centralized Management | >= 5.1.0, <= 5.2.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/103441Third Party AdvisoryVDB Entry
- https://support.f5.com/csp/article/K35195140MitigationVendor Advisory
- http://www.securityfocus.com/bid/103441Third Party AdvisoryVDB Entry
- https://support.f5.com/csp/article/K35195140MitigationVendor Advisory
FAQ
What is CVE-2017-6152?
CVE-2017-6152 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A local user on F5 BIG-IQ Centralized Management 5.1.0-5.2.0 with the Access Manager role has privileges to change the passwords of other users on the system, including the local admin account passwor...
How severe is CVE-2017-6152?
CVE-2017-6152 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-6152?
Check the references section above for vendor advisories and patch information. Affected products include: F5 Big-Iq Centralized Management.