CVE-2015-7393: High severity f5 big-iq application delivery controller vulnerability
dcoep in BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP AAM 11.4.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP AFM and PEM 11.3.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP DNS 12.0.0 before 12.0.0 HF1, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.2.0 through 11.3.0, BIG-IP GTM 11.2.0 through 11.6.0, BIG-IP PSM 11.2.0 through 11.4.1, Enterprise Manager 3.0.0 through 3.1.1, BIG-IQ Cloud 4.0.0 through 4.5.0, BIG-IQ Device 4.2.0 through 4.5.0, BIG-IQ Security 4.0.0 through 4.5.0, BIG-IQ ADC 4.5.0, BIG-IQ Centralized Management 4.6.0, and BIG-IQ Cloud and Orchestration 1.0.0 allows local users with advanced shell (bash) access to gain privileges via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7393?
CVE-2015-7393 is classified as a high-severity vulnerability due to its potential to allow unauthorized access to sensitive data.
What products are affected by CVE-2015-7393?
CVE-2015-7393 affects various versions of F5 BIG-IP components, including LTM, APM, ASM, and others between versions 11.2.0 and 12.0.0 before HF1.
How do I fix CVE-2015-7393?
To resolve CVE-2015-7393, it is recommended to upgrade all affected F5 BIG-IP products to the latest version or apply the appropriate hotfix as provided by F5.
Can CVE-2015-7393 be exploited remotely?
Yes, CVE-2015-7393 can be exploited remotely, making it critical to patch affected systems as soon as possible.
What types of attacks are possible due to CVE-2015-7393?
CVE-2015-7393 could allow attackers to perform unauthorized actions, potentially leading to data breaches or service disruptions.