On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.1-11.6.5 and BIG-IQ 5.2.0-7.1.0, a user associated with the Resource Administrator role who has access to the secure copy (scp) utility but does not have access to Advanced Shell (bash) can execute arbitrary commands using a maliciously crafted scp request.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-27027 On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.1-11.6.5 and BIG-IQ 5.2.0-7.1.0, a user associated with the Resource Administrator role who has access to the secure copy (scp) utility but does not have access to Advanced Shell (bash) can execute arbitrary commands using a maliciously crafted scp request.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published:

Updated: 2024-08-04T08:47:40.043Z

Reserved: 2020-01-06T00:00:00

Link: CVE-2020-5873

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-04-30T21:15:16.510

Modified: 2024-11-21T05:34:44.597

Link: CVE-2020-5873

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses