Vulnerability Description
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 11.6.1 HF1, and 12.0.0 through 12.1.2 on VIPRION platforms only, the script which synchronizes SafeNet External Network HSM configuration elements between blades in a clustered deployment will log the HSM partition password in cleartext to the "/var/log/ltm" log file.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Ip Access Policy Manager | 11.5.1 |
| F5 | Big-Ip Advanced Firewall Manager | 11.5.1 |
| F5 | Big-Ip Analytics | 11.5.1 |
| F5 | Big-Ip Application Acceleration Manager | 11.5.1 |
| F5 | Big-Ip Application Security Manager | 11.5.1 |
| F5 | Big-Ip Domain Name System | 11.5.1 |
| F5 | Big-Ip Global Traffic Manager | 11.5.1 |
| F5 | Big-Ip Link Controller | 11.5.1 |
| F5 | Big-Ip Local Traffic Manager | 11.5.1 |
| F5 | Big-Ip Policy Enforcement Manager | 11.5.1 |
| F5 | Big-Ip Websafe | 11.5.1 |
| F5 | Viprion Application Delivery Controller | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/101543Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039638Third Party AdvisoryVDB Entry
- https://support.f5.com/csp/article/K74759095Vendor Advisory
- http://www.securityfocus.com/bid/101543Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039638Third Party AdvisoryVDB Entry
- https://support.f5.com/csp/article/K74759095Vendor Advisory
FAQ
What is CVE-2017-6165?
CVE-2017-6165 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 11.6.1 HF1, and 12.0.0 through 12.1.2 on VIPRION platforms on...
How severe is CVE-2017-6165?
CVE-2017-6165 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-6165?
Check the references section above for vendor advisories and patch information. Affected products include: F5 Big-Ip Access Policy Manager, F5 Big-Ip Advanced Firewall Manager, F5 Big-Ip Analytics, F5 Big-Ip Application Acceleration Manager, F5 Big-Ip Application Security Manager.