Vulnerability Description
On BIG-IP versions 15.0.0-15.0.1, 14.1.0.2-14.1.2.2, 14.0.0.5-14.0.1, 13.1.1.5-13.1.3.1, 12.1.4.1-12.1.5, 11.6.4-11.6.5, and 11.5.9-11.5.10, the access controls implemented by scp.whitelist and scp.blacklist are not properly enforced for paths that are symlinks. This allows authenticated users with SCP access to overwrite certain configuration files that would otherwise be restricted.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Ip Access Policy Manager | >= 11.5.9, <= 11.5.10 |
| F5 | Big-Ip Advanced Firewall Manager | >= 11.5.9, <= 11.5.10 |
| F5 | Big-Ip Analytics | >= 11.5.9, <= 11.5.10 |
| F5 | Big-Ip Application Acceleration Manager | >= 11.5.9, <= 11.5.10 |
| F5 | Big-Ip Application Security Manager | >= 11.5.9, <= 11.5.10 |
| F5 | Big-Ip Domain Name System | >= 11.5.9, <= 11.5.10 |
| F5 | Big-Ip Edge Gateway | >= 11.5.9, <= 11.5.10 |
| F5 | Big-Ip Fraud Protection Service | >= 11.5.9, <= 11.5.10 |
| F5 | Big-Ip Global Traffic Manager | >= 11.5.9, <= 11.5.10 |
| F5 | Big-Ip Link Controller | >= 11.5.9, <= 11.5.10 |
| F5 | Big-Ip Local Traffic Manager | >= 11.5.9, <= 11.5.10 |
| F5 | Big-Ip Policy Enforcement Manager | >= 11.5.9, <= 11.5.10 |
| F5 | Big-Ip Webaccelerator | >= 11.5.9, <= 11.5.10 |
Related Weaknesses (CWE)
References
- https://support.f5.com/csp/article/K54336216Vendor Advisory
- https://support.f5.com/csp/article/K54336216Vendor Advisory
FAQ
What is CVE-2019-6679?
CVE-2019-6679 is a vulnerability with a CVSS score of 3.3 (LOW). On BIG-IP versions 15.0.0-15.0.1, 14.1.0.2-14.1.2.2, 14.0.0.5-14.0.1, 13.1.1.5-13.1.3.1, 12.1.4.1-12.1.5, 11.6.4-11.6.5, and 11.5.9-11.5.10, the access controls implemented by scp.whitelist and scp.bl...
How severe is CVE-2019-6679?
CVE-2019-6679 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6679?
Check the references section above for vendor advisories and patch information. Affected products include: F5 Big-Ip Access Policy Manager, F5 Big-Ip Advanced Firewall Manager, F5 Big-Ip Analytics, F5 Big-Ip Application Acceleration Manager, F5 Big-Ip Application Security Manager.