CVE-2018-15328: Infoleak
On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWorkflow 2.x, the passphrases for SNMPv3 users and trap destinations that are used for authentication and privacy are not handled by the BIG-IP system Secure Vault feature; they are written in the clear to the various configuration files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-15328?
CVE-2018-15328 has been classified with a severity rating indicating a significant risk due to the exposure of sensitive passphrases.
How do I fix CVE-2018-15328?
To resolve CVE-2018-15328, ensure that your system configurations utilize secure methods to handle SNMPv3 passphrases by upgrading to a patched version of the software.
Which versions are affected by CVE-2018-15328?
CVE-2018-15328 affects multiple versions of BIG-IP including 11.x to 14.x, Enterprise Manager 3.1.1, and several versions of BIG-IQ and iWorkflow.
What should I do if I cannot upgrade due to CVE-2018-15328?
If upgrading is not an option for CVE-2018-15328, consider implementing additional security measures like network segmentation and enhanced monitoring.
What are the implications of CVE-2018-15328 for my organization?
The implications of CVE-2018-15328 for your organization include potential unauthorized access to network management systems due to the exposure of authentication and privacy passphrases.