CVE-2017-6145: High severity F5 BIG-IP Access Policy Manager vulnerability
iControl REST in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.0.0 through 12.1.2 and 13.0.0 includes a service to convert authorization BIGIPAuthCookie cookies to X-F5-Auth-Token tokens. This service does not properly re-validate cookies when making that conversion, allowing once-valid but now expired cookies to be converted to valid tokens.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6145?
CVE-2017-6145 has been assigned a CVSS score that indicates it is a medium severity vulnerability.
How do I fix CVE-2017-6145?
To fix CVE-2017-6145, you should upgrade to a patched version of the affected F5 BIG-IP software.
Which versions are affected by CVE-2017-6145?
CVE-2017-6145 affects F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe versions 12.0.0 through 12.1.2 and 13.0.0.
What is CVE-2017-6145 about?
CVE-2017-6145 involves improper cookie validation in the iControl REST API of multiple F5 BIG-IP products that could be exploited to impersonate users.
Is there a workaround for CVE-2017-6145?
While upgrading to a secure version is recommended, temporary measures may include restricting access to the affected REST API services.