Vulnerability Name: CVE-2016-5736 (CCN-116022) Assigned: 2016-08-10 Published: 2016-08-10 Updated: 2019-06-06 Summary: The default configuration of the IPsec IKE peer listener in F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.1 before HF16, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF2; BIG-IP AAM, AFM, and PEM 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF2; BIG-IP DNS 12.x before 12.0.0 HF2; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.2.1 before HF16; BIG-IP GTM 11.2.1 before HF16, 11.4.x, 11.5.x before 11.5.4 HF2, and 11.6.x before 11.6.1; and BIG-IP PSM 11.4.0 through 11.4.1 improperly enables the anonymous IPsec IKE peer configuration object, which allows remote attackers to establish an IKE Phase 1 negotiation and possibly conduct brute-force attacks against Phase 2 negotiations via unspecified vectors. CVSS v3 Severity: 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H )6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): High
7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L )6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): Low
CVSS v2 Severity: 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
Vulnerability Type: CWE-284 Vulnerability Consequences: Bypass Security References: Source: MITRE Type: CNACVE-2016-5736 Source: SECTRACK Type: Third Party Advisory, VDB Entry1036618 Source: XF Type: UNKNOWNbigip-cve20165736-sec-bypass(116022) Source: CCN Type: F5 Security Advisory SOL10133477BIG-IP IPsec IKE peer listener vulnerability CVE-2016-5736 Source: CONFIRM Type: Vendor Advisoryhttps://support.f5.com/kb/en-us/solutions/public/k/10/sol10133477.html Vulnerable Configuration: Configuration 1 :cpe:/a:f5:big-ip_application_acceleration_manager:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:11.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:11.5.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:11.5.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:11.5.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:11.5.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:11.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:12.0.0:*:*:*:*:*:*:* Configuration 2 :cpe:/a:f5:big-ip_webaccelerator:11.2.1:*:*:*:*:*:*:* Configuration 3 :cpe:/a:f5:big-ip_analytics:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:11.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:11.5.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:11.5.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:11.5.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:11.5.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:11.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:12.0.0:*:*:*:*:*:*:* Configuration 4 :cpe:/a:f5:big-ip_domain_name_system:12.0.0:*:*:*:*:*:*:* Configuration 5 :cpe:/a:f5:big-ip_edge_gateway:11.2.1:*:*:*:*:*:*:* Configuration 6 :cpe:/a:f5:big-ip_access_policy_manager:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.5.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.5.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.5.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.5.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:12.0.0:*:*:*:*:*:*:* Configuration 7 :cpe:/a:f5:big-ip_local_traffic_manager:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.5.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.5.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.5.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.5.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:12.0.0:*:*:*:*:*:*:* Configuration 8 :cpe:/a:f5:big-ip_advanced_firewall_manager:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:11.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:11.5.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:11.5.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:11.5.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:11.5.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:11.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:12.0.0:*:*:*:*:*:*:* Configuration 9 :cpe:/a:f5:big-ip_websafe:11.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_websafe:12.0.0:*:*:*:*:*:*:* Configuration 10 :cpe:/a:f5:big-ip_policy_enforcement_manager:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:11.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:11.5.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:11.5.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:11.5.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:11.5.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:11.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:12.0.0:*:*:*:*:*:*:* Configuration 11 :cpe:/a:f5:big-ip_global_traffic_manager:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:11.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:11.5.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:11.5.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:11.5.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:11.5.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:11.6.0:*:*:*:*:*:*:* Configuration 12 :cpe:/a:f5:big-ip_link_controller:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.5.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.5.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.5.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.5.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:12.0.0:*:*:*:*:*:*:* Configuration 13 :cpe:/a:f5:big-ip_protocol_security_module:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_protocol_security_module:11.4.1:*:*:*:*:*:*:* Configuration 14 :cpe:/a:f5:big-ip_wan_optimization_manager:11.2.1:*:*:*:*:*:*:* Configuration 15 :cpe:/a:f5:big-ip_access_policy_manager:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.5.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.5.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.5.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.5.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:12.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.4.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.5.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.5.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.5.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.5.4:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:11.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:12.0.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:f5:big-ip_advanced_firewall_manager:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.5.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:11.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:11.5.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.5.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:11.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:11.6.0:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
f5 big-ip application acceleration manager 11.4.0
f5 big-ip application acceleration manager 11.4.1
f5 big-ip application acceleration manager 11.5.0
f5 big-ip application acceleration manager 11.5.1
f5 big-ip application acceleration manager 11.5.2
f5 big-ip application acceleration manager 11.5.3
f5 big-ip application acceleration manager 11.5.4
f5 big-ip application acceleration manager 11.6.0
f5 big-ip application acceleration manager 12.0.0
f5 big-ip webaccelerator 11.2.1
f5 big-ip analytics 11.2.1
f5 big-ip analytics 11.4.0
f5 big-ip analytics 11.4.1
f5 big-ip analytics 11.5.0
f5 big-ip analytics 11.5.1
f5 big-ip analytics 11.5.2
f5 big-ip analytics 11.5.3
f5 big-ip analytics 11.5.4
f5 big-ip analytics 11.6.0
f5 big-ip analytics 12.0.0
f5 big-ip domain name system 12.0.0
f5 big-ip edge gateway 11.2.1
f5 big-ip access policy manager 11.2.1
f5 big-ip access policy manager 11.4.0
f5 big-ip access policy manager 11.4.1
f5 big-ip access policy manager 11.5.0
f5 big-ip access policy manager 11.5.1
f5 big-ip access policy manager 11.5.2
f5 big-ip access policy manager 11.5.3
f5 big-ip access policy manager 11.5.4
f5 big-ip access policy manager 11.6.0
f5 big-ip access policy manager 12.0.0
f5 big-ip local traffic manager 11.2.1
f5 big-ip local traffic manager 11.4.0
f5 big-ip local traffic manager 11.4.1
f5 big-ip local traffic manager 11.5.0
f5 big-ip local traffic manager 11.5.1
f5 big-ip local traffic manager 11.5.2
f5 big-ip local traffic manager 11.5.3
f5 big-ip local traffic manager 11.5.4
f5 big-ip local traffic manager 11.6.0
f5 big-ip local traffic manager 12.0.0
f5 big-ip advanced firewall manager 11.4.0
f5 big-ip advanced firewall manager 11.4.1
f5 big-ip advanced firewall manager 11.5.0
f5 big-ip advanced firewall manager 11.5.1
f5 big-ip advanced firewall manager 11.5.2
f5 big-ip advanced firewall manager 11.5.3
f5 big-ip advanced firewall manager 11.5.4
f5 big-ip advanced firewall manager 11.6.0
f5 big-ip advanced firewall manager 12.0.0
f5 big-ip websafe 11.6.0
f5 big-ip websafe 12.0.0
f5 big-ip policy enforcement manager 11.4.0
f5 big-ip policy enforcement manager 11.4.1
f5 big-ip policy enforcement manager 11.5.0
f5 big-ip policy enforcement manager 11.5.1
f5 big-ip policy enforcement manager 11.5.2
f5 big-ip policy enforcement manager 11.5.3
f5 big-ip policy enforcement manager 11.5.4
f5 big-ip policy enforcement manager 11.6.0
f5 big-ip policy enforcement manager 12.0.0
f5 big-ip global traffic manager 11.2.1
f5 big-ip global traffic manager 11.4.0
f5 big-ip global traffic manager 11.4.1
f5 big-ip global traffic manager 11.5.0
f5 big-ip global traffic manager 11.5.1
f5 big-ip global traffic manager 11.5.2
f5 big-ip global traffic manager 11.5.3
f5 big-ip global traffic manager 11.5.4
f5 big-ip global traffic manager 11.6.0
f5 big-ip link controller 11.2.1
f5 big-ip link controller 11.4.0
f5 big-ip link controller 11.4.1
f5 big-ip link controller 11.5.0
f5 big-ip link controller 11.5.1
f5 big-ip link controller 11.5.2
f5 big-ip link controller 11.5.3
f5 big-ip link controller 11.5.4
f5 big-ip link controller 11.6.0
f5 big-ip link controller 12.0.0
f5 big-ip protocol security module 11.4.0
f5 big-ip protocol security module 11.4.1
f5 big-ip wan optimization manager 11.2.1
f5 big-ip access policy manager 11.2.1
f5 big-ip access policy manager 11.4.0
f5 big-ip access policy manager 11.4.1
f5 big-ip access policy manager 11.5.0
f5 big-ip access policy manager 11.5.1
f5 big-ip access policy manager 11.5.2
f5 big-ip access policy manager 11.5.3
f5 big-ip access policy manager 11.5.4
f5 big-ip access policy manager 11.6.0
f5 big-ip access policy manager 12.0.0
f5 big-ip application security manager 11.2.1
f5 big-ip application security manager 11.4.0
f5 big-ip application security manager 11.4.1
f5 big-ip application security manager 11.5.0
f5 big-ip application security manager 11.5.1
f5 big-ip application security manager 11.5.2
f5 big-ip application security manager 11.5.3
f5 big-ip application security manager 11.5.4
f5 big-ip application security manager 11.6.0
f5 big-ip application security manager 12.0.0
f5 big-ip advanced firewall manager 11.5.1
f5 big-ip global traffic manager 11.5.1
f5 big-ip link controller 11.5.1
f5 big-ip access policy manager 11.4.0
f5 big-ip link controller 11.5.0
f5 big-ip local traffic manager 11.5.0
f5 big-ip local traffic manager 11.6.0
f5 big-ip advanced firewall manager 11.6.0