CVE-2017-6152: Medium severity F5 BIG-IQ Centralized Management vulnerability
Published Mar 8, 2018
·Updated
A local user on F5 BIG-IQ Centralized Management 5.1.0-5.2.0 with the Access Manager role has privileges to change the passwords of other users on the system, including the local admin account password.
Affected Software
1 affected component
F5 BIG-IQ Centralized Management>=5.1.0<=5.2.0
Event History
Mar 8, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-6152?
CVE-2017-6152 is considered a critical vulnerability due to potential unauthorized access to user accounts.
2
How do I fix CVE-2017-6152?
To fix CVE-2017-6152, upgrade F5 BIG-IQ Centralized Management to version 5.2.0 or higher.
3
Who is affected by CVE-2017-6152?
CVE-2017-6152 affects local users with the Access Manager role on F5 BIG-IQ Centralized Management versions 5.1.0 to 5.2.0.
4
What are the potential risks of CVE-2017-6152?
The risks of CVE-2017-6152 include unauthorized password changes potentially compromising sensitive accounts.
5
Is there a workaround for CVE-2017-6152?
There are no official workarounds for CVE-2017-6152; updating to the latest version is the only recommended action.