Vulnerability Name: CVE-2017-6145 (CCN-133873) Assigned: 2017-07-19 Published: 2017-07-19 Updated: 2017-11-15 Summary: iControl REST in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.0.0 through 12.1.2 and 13.0.0 includes a service to convert authorization BIGIPAuthCookie cookies to X-F5-Auth-Token tokens. This service does not properly re-validate cookies when making that conversion, allowing once-valid but now expired cookies to be converted to valid tokens. CVSS v3 Severity: 7.3 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L )6.4 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): Low
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N )6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): HighAvailibility (A): None
CVSS v2 Severity: 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:C/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): CompleteAvailibility (A): None
Vulnerability Type: CWE-613 Vulnerability Consequences: Bypass Security References: Source: MITRE Type: CNACVE-2017-6145 Source: XF Type: UNKNOWNf5-cve20176145-sec-bypass(133873) Source: CCN Type: F5 Security Advisory K22317030iControl REST vulnerability CVE-2017-6145 Source: CONFIRM Type: Mitigation, Vendor Advisoryhttps://support.f5.com/csp/article/K22317030 Vulnerable Configuration: Configuration 1 :cpe:/a:f5:big-ip_access_policy_manager:12.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:12.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:12.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:12.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:12.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:12.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:12.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:12.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:12.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:12.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_domain_name_system:12.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_domain_name_system:12.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_domain_name_system:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_domain_name_system:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:12.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:12.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:12.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:12.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:12.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:12.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_websafe:12.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_websafe:12.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_websafe:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_websafe:13.0.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:f5:big-ip_local_traffic_manager:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_afm:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_asm:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_dns:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_pem:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_websafe:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_access_policy_manager:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_websafe:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:12.1.2:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_dns:12.1.2:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
f5 big-ip access policy manager 12.1.0
f5 big-ip access policy manager 12.1.1
f5 big-ip access policy manager 12.1.2
f5 big-ip access policy manager 13.0.0
f5 big-ip advanced firewall manager 12.1.0
f5 big-ip advanced firewall manager 12.1.1
f5 big-ip advanced firewall manager 12.1.2
f5 big-ip advanced firewall manager 13.0.0
f5 big-ip analytics 12.1.0
f5 big-ip analytics 12.1.1
f5 big-ip analytics 12.1.2
f5 big-ip analytics 13.0.0
f5 big-ip application acceleration manager 12.1.0
f5 big-ip application acceleration manager 12.1.1
f5 big-ip application acceleration manager 12.1.2
f5 big-ip application acceleration manager 13.0.0
f5 big-ip application security manager 12.1.0
f5 big-ip application security manager 12.1.1
f5 big-ip application security manager 12.1.2
f5 big-ip application security manager 13.0.0
f5 big-ip domain name system 12.1.0
f5 big-ip domain name system 12.1.1
f5 big-ip domain name system 12.1.2
f5 big-ip domain name system 13.0.0
f5 big-ip link controller 12.1.0
f5 big-ip link controller 12.1.1
f5 big-ip link controller 12.1.2
f5 big-ip link controller 13.0.0
f5 big-ip local traffic manager 12.1.0
f5 big-ip local traffic manager 12.1.1
f5 big-ip local traffic manager 12.1.2
f5 big-ip local traffic manager 13.0.0
f5 big-ip policy enforcement manager 12.1.0
f5 big-ip policy enforcement manager 12.1.1
f5 big-ip policy enforcement manager 12.1.2
f5 big-ip policy enforcement manager 13.0.0
f5 big-ip websafe 12.1.0
f5 big-ip websafe 12.1.1
f5 big-ip websafe 12.1.2
f5 big-ip websafe 13.0.0
f5 big-ip local traffic manager 13.0.0
f5 big-ip aam 13.0.0
f5 big-ip afm 13.0.0
f5 big-ip analytics 13.0.0
f5 big-ip access policy manager 13.0.0
f5 big-ip asm 13.0.0
f5 big-ip dns 13.0.0
f5 big-ip link controller 13.0.0
f5 big-ip pem 13.0.0
f5 big-ip websafe 13.0.0
f5 big-ip local traffic manager 12.1.2
f5 big-ip access policy manager 12.1.2
f5 big-ip link controller 12.1.2
f5 big-ip websafe 12.1.2
f5 big-ip analytics 12.1.2
f5 big-ip dns 12.1.2