Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-6600


In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, when remote authentication is enabled for administrative users and all external users are granted the "guest" role, unsanitized values can be reflected to the client via the login page. This can lead to a cross-site scripting attack against unauthenticated clients.


Published

2019-03-13T22:29:00.550

Last Modified

2024-11-21T04:46:46.860

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application f5 big-ip_local_traffic_manager ≤ 11.5.8 Yes
Application f5 big-ip_local_traffic_manager ≤ 11.6.3.2 Yes
Application f5 big-ip_local_traffic_manager ≤ 12.1.3.7 Yes
Application f5 big-ip_local_traffic_manager ≤ 13.1.1.3 Yes
Application f5 big-ip_local_traffic_manager ≤ 14.0.0.2 Yes
Application f5 big-ip_application_acceleration_manager ≤ 11.5.8 Yes
Application f5 big-ip_application_acceleration_manager ≤ 11.6.3.2 Yes
Application f5 big-ip_application_acceleration_manager ≤ 12.1.3.7 Yes
Application f5 big-ip_application_acceleration_manager ≤ 13.1.1.3 Yes
Application f5 big-ip_application_acceleration_manager ≤ 14.0.0.2 Yes
Application f5 big-ip_advanced_firewall_manager ≤ 11.5.8 Yes
Application f5 big-ip_advanced_firewall_manager ≤ 11.6.3.2 Yes
Application f5 big-ip_advanced_firewall_manager ≤ 12.1.3.7 Yes
Application f5 big-ip_advanced_firewall_manager ≤ 13.1.1.3 Yes
Application f5 big-ip_advanced_firewall_manager ≤ 14.0.0.2 Yes
Application f5 big-ip_analytics ≤ 11.5.8 Yes
Application f5 big-ip_analytics ≤ 11.6.3.2 Yes
Application f5 big-ip_analytics ≤ 12.1.3.7 Yes
Application f5 big-ip_analytics ≤ 13.1.1.3 Yes
Application f5 big-ip_analytics ≤ 14.0.0.2 Yes
Application f5 big-ip_access_policy_manager ≤ 11.5.8 Yes
Application f5 big-ip_access_policy_manager ≤ 11.6.3.2 Yes
Application f5 big-ip_access_policy_manager ≤ 12.1.3.7 Yes
Application f5 big-ip_access_policy_manager ≤ 13.1.1.3 Yes
Application f5 big-ip_access_policy_manager ≤ 14.0.0.2 Yes
Application f5 big-ip_application_security_manager ≤ 11.5.8 Yes
Application f5 big-ip_application_security_manager ≤ 11.6.3.2 Yes
Application f5 big-ip_application_security_manager ≤ 12.1.3.7 Yes
Application f5 big-ip_application_security_manager ≤ 13.1.1.3 Yes
Application f5 big-ip_application_security_manager ≤ 14.0.0.2 Yes
Application f5 big-ip_domain_name_system ≤ 11.5.8 Yes
Application f5 big-ip_domain_name_system ≤ 11.6.3.2 Yes
Application f5 big-ip_domain_name_system ≤ 12.1.3.7 Yes
Application f5 big-ip_domain_name_system ≤ 13.1.1.3 Yes
Application f5 big-ip_domain_name_system ≤ 14.0.0.2 Yes
Application f5 big-ip_edge_gateway ≤ 11.5.8 Yes
Application f5 big-ip_edge_gateway ≤ 11.6.3.2 Yes
Application f5 big-ip_edge_gateway ≤ 12.1.3.7 Yes
Application f5 big-ip_edge_gateway ≤ 13.1.1.3 Yes
Application f5 big-ip_edge_gateway ≤ 14.0.0.2 Yes
Application f5 big-ip_fraud_protection_service ≤ 11.5.8 Yes
Application f5 big-ip_fraud_protection_service ≤ 11.6.3.2 Yes
Application f5 big-ip_fraud_protection_service ≤ 12.1.3.7 Yes
Application f5 big-ip_fraud_protection_service ≤ 13.1.1.3 Yes
Application f5 big-ip_fraud_protection_service ≤ 14.0.0.2 Yes
Application f5 big-ip_global_traffic_manager ≤ 11.5.8 Yes
Application f5 big-ip_global_traffic_manager ≤ 11.6.3.2 Yes
Application f5 big-ip_global_traffic_manager ≤ 12.1.3.7 Yes
Application f5 big-ip_global_traffic_manager ≤ 13.1.1.3 Yes
Application f5 big-ip_global_traffic_manager ≤ 14.0.0.2 Yes
Application f5 big-ip_link_controller ≤ 11.5.8 Yes
Application f5 big-ip_link_controller ≤ 11.6.3.2 Yes
Application f5 big-ip_link_controller ≤ 12.1.3.7 Yes
Application f5 big-ip_link_controller ≤ 13.1.1.3 Yes
Application f5 big-ip_link_controller ≤ 14.0.0.2 Yes
Application f5 big-ip_policy_enforcement_manager ≤ 11.5.8 Yes
Application f5 big-ip_policy_enforcement_manager ≤ 11.6.3.2 Yes
Application f5 big-ip_policy_enforcement_manager ≤ 12.1.3.7 Yes
Application f5 big-ip_policy_enforcement_manager ≤ 13.1.1.3 Yes
Application f5 big-ip_policy_enforcement_manager ≤ 14.0.0.2 Yes
Application f5 big-ip_webaccelerator ≤ 11.5.8 Yes
Application f5 big-ip_webaccelerator ≤ 11.6.3.2 Yes
Application f5 big-ip_webaccelerator ≤ 12.1.3.7 Yes
Application f5 big-ip_webaccelerator ≤ 13.1.1.3 Yes
Application f5 big-ip_webaccelerator ≤ 14.0.0.2 Yes

References