CVE Database
/

CVE-2019-6642

Back to search

CVE-2019-6642

Published: Jul 1, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, authenticated users with the ability to upload files (via scp, for example) can escalate their privileges to allow root shell access from within the TMOS Shell (tmsh) interface. The tmsh interface allows users to execute a secondary program via tools like sftp or scp.

VendorProductVersions

F5

BIG-IP, BIG-IQ, iWorkflow, Enterprise Manager

affected
BIG-IP 15.0.0
affected
14.0.0-14.1.0.5
affected
13.0.0-13.1.1.5
affected
12.1.0-12.1.4.2
affected
11.5.2-11.6.4

+4 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now