Metrics
No CVSS v4.0
No CVSS v3.1
Attack Vector Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None
This CVE is not in the KEV list.
The EPSS score is 0.0047.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
F5
Subscribe
|
Big-ip Access Policy Manager
Subscribe
Big-ip Advanced Firewall Manager
Subscribe
Big-ip Analytics
Subscribe
Big-ip Application Acceleration Manager
Subscribe
Big-ip Application Security Manager
Subscribe
Big-ip Domain Name System
Subscribe
Big-ip Edge Gateway
Subscribe
Big-ip Fraud Protection Service
Subscribe
Big-ip Global Traffic Manager
Subscribe
Big-ip I10600
Subscribe
Big-ip I10800
Subscribe
Big-ip I11600
Subscribe
Big-ip I11800
Subscribe
Big-ip I15600
Subscribe
Big-ip I15800
Subscribe
Big-ip I2000s
Subscribe
Big-ip I2200s
Subscribe
Big-ip I4000s
Subscribe
Big-ip I4200v
Subscribe
Big-ip I5000s
Subscribe
Big-ip I5050s
Subscribe
Big-ip I5200v
Subscribe
Big-ip I5250v
Subscribe
Big-ip I5250v Fips
Subscribe
Big-ip I7000
Subscribe
Big-ip I7050s
Subscribe
Big-ip I7055s
Subscribe
Big-ip I7200v
Subscribe
Big-ip I7200v-ssl
Subscribe
Big-ip I7200v Fips
Subscribe
Big-ip I7250v
Subscribe
Big-ip I7255s
Subscribe
Big-ip Link Controller
Subscribe
Big-ip Local Traffic Manager
Subscribe
Big-ip Policy Enforcement Manager
Subscribe
Big-ip Webaccelerator
Subscribe
Big-ip Webaccelerator12.1.1
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
| AND |
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
| AND |
|
Configuration 10 [-]
| AND |
|
Configuration 11 [-]
| AND |
|
Configuration 12 [-]
| AND |
|
Configuration 13 [-]
| AND |
|
No data.
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-16168 | Platform dependent weakness. This issue only impacts iSeries platforms. On these platforms, in BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator) versions 14.0.0-14.1.0.1, 13.0.0-13.1.1.3, and 12.1.1 HF2-12.1.4, the secureKeyCapable attribute was not set which causes secure vault to not use the F5 hardware support to store the unit key. Instead the unit key is stored in plaintext on disk as would be the case for Z100 systems. Additionally this causes the unit key to be stored in UCS files taken on these platforms. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://support.f5.com/csp/article/K18535734 |
|
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: f5
Published:
Updated: 2024-08-04T20:23:22.059Z
Reserved: 2019-01-22T00:00:00
Link: CVE-2019-6609
No data.
Status : Modified
Published: 2019-04-15T15:29:00.920
Modified: 2024-11-21T04:46:47.907
Link: CVE-2019-6609
No data.
OpenCVE Enrichment
No data.
EUVD