First published: Wed Mar 07 2018(Updated: )
A local user on F5 BIG-IQ Centralized Management 5.1.0-5.2.0 with the Access Manager role has privileges to change the passwords of other users on the system, including the local admin account password.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP and BIG-IQ Centralized Management | >=5.1.0<=5.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6152 is considered a critical vulnerability due to potential unauthorized access to user accounts.
To fix CVE-2017-6152, upgrade F5 BIG-IQ Centralized Management to version 5.2.0 or higher.
CVE-2017-6152 affects local users with the Access Manager role on F5 BIG-IQ Centralized Management versions 5.1.0 to 5.2.0.
The risks of CVE-2017-6152 include unauthorized password changes potentially compromising sensitive accounts.
There are no official workarounds for CVE-2017-6152; updating to the latest version is the only recommended action.