First published: Wed Oct 05 2016(Updated: )
F5 BIG-IP LTM systems 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF11, 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2 allow remote attackers to modify or extract system configuration files via vectors involving NAT64.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Local Traffic Manager | =11.0.0 | |
F5 BIG-IP Local Traffic Manager | =11.1.0 | |
F5 BIG-IP Local Traffic Manager | =11.2.0 | |
F5 BIG-IP Local Traffic Manager | =11.2.1 | |
F5 BIG-IP Local Traffic Manager | =11.3.0 | |
F5 BIG-IP Local Traffic Manager | =11.4.0 | |
F5 BIG-IP Local Traffic Manager | =11.4.1 | |
F5 BIG-IP Local Traffic Manager | =11.5.0 | |
F5 BIG-IP Local Traffic Manager | =11.5.1 | |
F5 BIG-IP Local Traffic Manager | =11.5.2 | |
F5 BIG-IP Local Traffic Manager | =11.5.3 | |
F5 BIG-IP Local Traffic Manager | =11.5.4 | |
F5 BIG-IP Local Traffic Manager | =11.6.0 | |
F5 BIG-IP Local Traffic Manager | =11.6.1 | |
F5 BIG-IP Local Traffic Manager | =12.0.0 | |
F5 BIG-IP Local Traffic Manager | =12.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5745 has a severity rating of high due to its potential for remote attackers to modify or extract critical system configuration files.
To fix CVE-2016-5745, upgrade your F5 BIG-IP LTM systems to the latest version as specified in the F5 advisory.
Affected versions include F5 BIG-IP LTM 11.x before 11.2.1 HF16, and various 11.3.x, 11.4.x, 11.5.x, 11.6.x, and 12.x versions before specific hotfixes.
Yes, CVE-2016-5745 can be exploited remotely, allowing attackers to affect the system's configuration without physical access.
CVE-2016-5745 can lead to unauthorized access to and modification of system configuration files, compromising the integrity of the BIG-IP system.