QID 376141
Date Published: 2021-12-20
QID 376141: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) Privilege Escalation Vulnerability (K84583382)
VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may result in a local privilege escalation.CVE-2015-5191
Vulnerable Component: BIG-IP ASM,LTM,APM
Affected Versions:
15.1.0 - 15.1.4
14.1.0 - 14.1.4
13.1.0 - 13.1.4
12.1.0 - 12.1.6
11.6.1 - 11.6.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
This vulnerability may allow a local user to gain elevated privileges on the system.
Solution
The vendor has released patch, for more information please visit: K84583382
Vendor References
- K84583382 -
support.f5.com/csp/article/K84583382
CVEs related to QID 376141
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K84583382 |
|