The svpn component of the F5 BIG-IP APM client prior to version 7.1.7 for Linux and Mac OS X runs as a privileged process and can allow an unprivileged user to assume super-user privileges on the local client host. A malicious local unprivileged user may gain knowledge of sensitive information, manipulate certain data, or disrupt service.
2018-07-12T18:29:00.577
2024-11-21T04:09:00.290
Modified
CVSSv3.0: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | f5 | big-ip_access_policy_manager | ≤ 7.1.6.1 | Yes |
| Application | f5 | big-ip_access_policy_manager | ≤ 11.5.6 | Yes |
| Application | f5 | big-ip_access_policy_manager | ≤ 12.1.3 | Yes |
| Application | f5 | big-ip_access_policy_manager | ≤ 13.1.0 | Yes |
| Application | f5 | big-ip_edge | ≤ 7150 | Yes |
| Operating System | apple | mac_os_x | - | No |
| Operating System | linux | linux_kernel | - | No |