QID 378015
Date Published: 2023-03-23
QID 378015: F5 BIG-IP Configuration utility Vulnerability (K29280193)
When authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.CVE-2019-6597
Vulnerable Component: BIG-IP ASM,APM,LTM
Affected Versions:
13.0.0 - 13.1.1
12.1.0 - 12.1.3
11.6.1 - 11.6.311.5.1 - 11.5.8
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
This vulnerability allows a privilege escalation for authenticated administrative users.
Solution
For more information about patch details please refer to K29280193
Vendor References
- K29280193 -
support.f5.com/csp/article/K29280193
CVEs related to QID 378015
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K29280193 |
|