CVE-2012-1493: High severity f5 application security manager vulnerability
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1493?
CVE-2012-1493 has a critical severity rating as it allows attackers to exploit the use of a single SSH private key across multiple installations.
How do I fix CVE-2012-1493?
To fix CVE-2012-1493, update your F5 BIG-IP appliances to the latest version that is not affected by this vulnerability, specifically versions after 9.4.8-HF5, 10.2.4, 11.0.0-HF2, or 11.1.0-HF3.
What systems are impacted by CVE-2012-1493?
CVE-2012-1493 affects F5 BIG-IP appliances across versions from 9.x to 11.1.x and also impacts older versions of Enterprise Manager.
What types of attacks can CVE-2012-1493 facilitate?
CVE-2012-1493 can facilitate unauthorized access to affected systems, potentially leading to data breaches and system compromise.
Is there a workaround for CVE-2012-1493 if an update isn’t immediately possible?
While the best solution is to apply the update, consider implementing strict access controls and monitoring SSH access as a temporary measure.