CVE-2013-7408: High severity f5 big-ip analytics vulnerability
Published Oct 26, 2014
·Updated
F5 BIG-IP Analytics 11.x before 11.4.0 uses a predictable session cookie, which makes it easier for remote attackers to have unspecified impact by guessing the value.
Affected Software
5 affected components
F5 BIG-IP Analytics=11.0.0
F5 BIG-IP Analytics=11.1.0
F5 BIG-IP Analytics=11.2.0
F5 BIG-IP Analytics=11.2.1
F5 BIG-IP Analytics=11.3.0
Event History
Oct 26, 2014
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-7408?
CVE-2013-7408 is considered to have a medium severity level due to the predictable session cookie vulnerability.
2
How do I fix CVE-2013-7408?
To fix CVE-2013-7408, upgrade to F5 BIG-IP Analytics version 11.4.0 or later.
3
What impact can CVE-2013-7408 have on my system?
CVE-2013-7408 can allow remote attackers to exploit session cookies, potentially gaining unauthorized access.
4
Which versions of F5 BIG-IP Analytics are affected by CVE-2013-7408?
CVE-2013-7408 affects F5 BIG-IP Analytics versions 11.0.0 to 11.3.0.
5
Is there a workaround for CVE-2013-7408?
There are no documented workarounds for CVE-2013-7408, so upgrading is the recommended solution.