QID 378016
Date Published: 2023-03-23
QID 378016: F5 BIG-IP Simple Network Management Protocol (SNMP) Vulnerability (K42027747)
The passphrases for SNMPv3 users and trap destinations that are used for authentication and privacy are not handled by the BIG-IP system Secure Vault feature; they are written in the clear to the various configuration files.CVE-2018-15328
Vulnerable Component: BIG-IP ASM,APM,LTM
Affected Versions:
14.0.0
13.0.0 - 13.1.1
12.1.0 - 12.1.4
11.2.1 - 11.6.3
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
BIG-IP, BIG-IQ, F5 iWorkflow, and Enterprise Manager
Solution
For more information about patch details please refer to K42027747
Vendor References
- K42027747 -
support.f5.com/csp/article/K42027747
CVEs related to QID 378016
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K42027747 |
|