First published: Mon Jul 01 2019(Updated: )
In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, authenticated users with the ability to upload files (via scp, for example) can escalate their privileges to allow root shell access from within the TMOS Shell (tmsh) interface. The tmsh interface allows users to execute a secondary program via tools like sftp or scp.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Access Policy Manager | >=11.5.2<=11.6.4 | |
F5 BIG-IP Access Policy Manager | >=12.1.0<=12.1.4.2 | |
F5 BIG-IP Access Policy Manager | >=13.0.0<=13.1.1.5 | |
F5 BIG-IP Access Policy Manager | >=14.0.0<=14.1.0.5 | |
F5 BIG-IP Access Policy Manager | =15.0.0 | |
F5 BIG-IP Advanced Firewall Manager | >=11.5.2<=11.6.4 | |
F5 BIG-IP Advanced Firewall Manager | >=12.1.0<=12.1.4.2 | |
F5 BIG-IP Advanced Firewall Manager | >=13.0.0<=13.1.1.5 | |
F5 BIG-IP Advanced Firewall Manager | >=14.0.0<=14.1.0.5 | |
F5 BIG-IP Advanced Firewall Manager | =15.0.0 | |
F5 Big-ip Application Acceleration Manager | >=11.5.2<=11.6.4 | |
F5 Big-ip Application Acceleration Manager | >=12.1.0<=12.1.4.2 | |
F5 Big-ip Application Acceleration Manager | >=13.0.0<=13.1.1.5 | |
F5 Big-ip Application Acceleration Manager | >=14.0.0<=14.1.0.5 | |
F5 Big-ip Application Acceleration Manager | =15.0.0 | |
F5 Big-ip Link Controller | >=11.5.2<=11.6.4 | |
F5 Big-ip Link Controller | >=12.1.0<=12.1.4.2 | |
F5 Big-ip Link Controller | >=13.0.0<=13.1.1.5 | |
F5 Big-ip Link Controller | >=14.0.0<=14.1.0.5 | |
F5 Big-ip Link Controller | =15.0.0 | |
F5 Big-ip Policy Enforcement Manager | >=11.5.2<=11.6.4 | |
F5 Big-ip Policy Enforcement Manager | >=12.1.0<=12.1.4.2 | |
F5 Big-ip Policy Enforcement Manager | >=13.0.0<=13.1.1.5 | |
F5 Big-ip Policy Enforcement Manager | >=14.0.0<=14.1.0.5 | |
F5 Big-ip Policy Enforcement Manager | =15.0.0 | |
F5 Big-ip Webaccelerator | >=11.5.2<=11.6.4 | |
F5 Big-ip Webaccelerator | >=12.1.0<=12.1.4.2 | |
F5 Big-ip Webaccelerator | >=13.0.0<=13.1.1.5 | |
F5 Big-ip Webaccelerator | >=14.0.0<=14.1.0.5 | |
F5 Big-ip Webaccelerator | =15.0.0 | |
F5 BIG-IP Application Security Manager | >=11.5.2<=11.6.4 | |
F5 BIG-IP Application Security Manager | >=12.1.0<=12.1.4.2 | |
F5 BIG-IP Application Security Manager | >=13.0.0<=13.1.1.5 | |
F5 BIG-IP Application Security Manager | >=14.0.0<=14.1.0.5 | |
F5 BIG-IP Application Security Manager | =15.0.0 | |
F5 Big-ip Local Traffic Manager | >=11.5.2<=11.6.4 | |
F5 Big-ip Local Traffic Manager | >=12.1.0<=12.1.4.2 | |
F5 Big-ip Local Traffic Manager | >=13.0.0<=13.1.1.5 | |
F5 Big-ip Local Traffic Manager | >=14.0.0<=14.1.0.5 | |
F5 Big-ip Local Traffic Manager | =15.0.0 | |
F5 Big-ip Fraud Protection Service | >=11.5.2<=11.6.4 | |
F5 Big-ip Fraud Protection Service | >=12.1.0<=12.1.4.2 | |
F5 Big-ip Fraud Protection Service | >=13.0.0<=13.1.1.5 | |
F5 Big-ip Fraud Protection Service | >=14.0.0<=14.1.0.5 | |
F5 Big-ip Fraud Protection Service | =15.0.0 | |
F5 Big-ip Global Traffic Manager | >=11.5.2<=11.6.4 | |
F5 Big-ip Global Traffic Manager | >=12.1.0<=12.1.4.2 | |
F5 Big-ip Global Traffic Manager | >=13.0.0<=13.1.1.5 | |
F5 Big-ip Global Traffic Manager | >=14.0.0<=14.1.0.5 | |
F5 Big-ip Global Traffic Manager | =15.0.0 | |
F5 BIG-IP Analytics | >=11.5.2<=11.6.4 | |
F5 BIG-IP Analytics | >=12.1.0<=12.1.4.2 | |
F5 BIG-IP Analytics | >=13.0.0<=13.1.1.5 | |
F5 BIG-IP Analytics | >=14.0.0<=14.1.0.5 | |
F5 BIG-IP Analytics | =15.0.0 | |
F5 Big-ip Edge Gateway | >=11.5.2<=11.6.4 | |
F5 Big-ip Edge Gateway | >=12.1.0<=12.1.4.2 | |
F5 Big-ip Edge Gateway | >=13.0.0<=13.1.1.5 | |
F5 Big-ip Edge Gateway | >=14.0.0<=14.1.0.5 | |
F5 Big-ip Edge Gateway | =15.0.0 | |
F5 Big-ip Domain Name System | >=11.5.2<=11.6.4 | |
F5 Big-ip Domain Name System | >=12.1.0<=12.1.4.2 | |
F5 Big-ip Domain Name System | >=13.0.0<=13.1.1.5 | |
F5 Big-ip Domain Name System | >=14.0.0<=14.1.0.5 | |
F5 Big-ip Domain Name System | =15.0.0 | |
F5 BIG-IQ Centralized Management | >=5.1.0<=5.4.0 | |
F5 BIG-IQ Centralized Management | >=6.0.0<=6.1.0 | |
F5 Enterprise Manager | =3.1.1 | |
F5 iWorkflow | =2.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.