CVE-2019-6642
Published: Jul 1, 2019
Modified: Aug 4, 2024
Description
In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, authenticated users with the ability to upload files (via scp, for example) can escalate their privileges to allow root shell access from within the TMOS Shell (tmsh) interface. The tmsh interface allows users to execute a secondary program via tools like sftp or scp.
| Vendor | Product | Versions |
|---|---|---|
F5 | BIG-IP, BIG-IQ, iWorkflow, Enterprise Manager | affected BIG-IP 15.0.0affected 14.0.0-14.1.0.5affected 13.0.0-13.1.1.5affected 12.1.0-12.1.4.2affected 11.5.2-11.6.4+4 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now