On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, under certain circumstances, attackers can decrypt configuration items that are encrypted because the vCMP configuration unit key is generated with insufficient randomness. The attack prerequisite is direct access to encrypted configuration and/or UCS files.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: f5
Published:
Updated: 2024-08-04T20:23:22.266Z
Reserved: 2019-01-22T00:00:00
Link: CVE-2019-6632

No data.

Status : Modified
Published: 2019-07-03T19:15:12.970
Modified: 2024-11-21T04:46:50.810
Link: CVE-2019-6632

No data.

No data.