Vulnerability Name: CVE-2018-15328 (CCN-154209) Assigned: 2018-12-12 Published: 2018-12-12 Updated: 2019-01-09 Summary: On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWorkflow 2.x, the passphrases for SNMPv3 users and trap destinations that are used for authentication and privacy are not handled by the BIG-IP system Secure Vault feature; they are written in the clear to the various configuration files. CVSS v3 Severity: 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N )6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): NoneAvailibility (A): None
6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N )5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): LowUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): NoneAvailibility (A): None
CVSS v2 Severity: 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): NoneAvailibility (A): None
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:N/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): CompleteIntegrity (I): NoneAvailibility (A): None
Vulnerability Type: CWE-200 Vulnerability Consequences: Obtain Information References: Source: MITRE Type: CNACVE-2018-15328 Source: BID Type: Third Party Advisory, VDB Entry106258 Source: XF Type: UNKNOWNf5-cve201815328-info-disc(154209) Source: CCN Type: F5 Security Advisory K42027747BIG-IP SNMP vulnerability CVE-2018-15328 Source: CONFIRM Type: Vendor Advisoryhttps://support.f5.com/csp/article/K42027747 Vulnerable Configuration: Configuration 1 :cpe:/a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.6.3)OR cpe:/a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3) OR cpe:/a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.1) OR cpe:/a:f5:big-ip_access_policy_manager:14.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.6.3) OR cpe:/a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3) OR cpe:/a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.1) OR cpe:/a:f5:big-ip_advanced_firewall_manager:14.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_analytics:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.6.3) OR cpe:/a:f5:big-ip_analytics:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3) OR cpe:/a:f5:big-ip_analytics:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.1) OR cpe:/a:f5:big-ip_analytics:14.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.6.3) OR cpe:/a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3) OR cpe:/a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.1) OR cpe:/a:f5:big-ip_application_acceleration_manager:14.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.6.3) OR cpe:/a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3) OR cpe:/a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.1) OR cpe:/a:f5:big-ip_application_security_manager:14.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.6.3) OR cpe:/a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3) OR cpe:/a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.1) OR cpe:/a:f5:big-ip_domain_name_system:14.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.6.3) OR cpe:/a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3) OR cpe:/a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.1) OR cpe:/a:f5:big-ip_edge_gateway:14.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.6.3) OR cpe:/a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3) OR cpe:/a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.1) OR cpe:/a:f5:big-ip_fraud_protection_service:14.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.6.3) OR cpe:/a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3) OR cpe:/a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.1) OR cpe:/a:f5:big-ip_global_traffic_manager:14.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.6.3) OR cpe:/a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3) OR cpe:/a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.1) OR cpe:/a:f5:big-ip_link_controller:14.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.6.3) OR cpe:/a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3) OR cpe:/a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.1) OR cpe:/a:f5:big-ip_local_traffic_manager:14.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.6.3) OR cpe:/a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3) OR cpe:/a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.1) OR cpe:/a:f5:big-ip_policy_enforcement_manager:14.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:* (Version >= 11.2.1 and <= 11.6.3) OR cpe:/a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:* (Version >= 12.1.0 and <= 12.1.3) OR cpe:/a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:* (Version >= 13.0.0 and <= 13.1.1) OR cpe:/a:f5:big-ip_webaccelerator:14.0.0:*:*:*:*:*:*:* Configuration 2 :cpe:/a:f5:enterprise_manager:3.1.1:*:*:*:*:*:*:* Configuration 3 :cpe:/a:f5:big-iq_centralized_management:4.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-iq_centralized_management:*:*:*:*:*:*:*:* (Version >= 5.0.0 and <= 5.4.0) OR cpe:/a:f5:big-iq_centralized_management:*:*:*:*:*:*:*:* (Version >= 6.0.0 and <= 6.0.1) Configuration 4 :cpe:/a:f5:iworkflow:*:*:*:*:*:*:*:* (Version >= 2.2.0 and <= 2.3.0)Configuration CCN 1 :cpe:/a:f5:enterprise_manager:3.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip:11.2.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip:12.1.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip:13.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-iq_centralized_management:5.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-iq_centralized_management:5.4.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-iq_centralized_management:4.6.0:*:*:*:*:*:*:* OR cpe:/a:f5:iworkflow:2.3.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip:12.1.3.7:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip:11.6.3:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip:13.1.1:*:*:*:*:*:*:* OR cpe:/a:f5:big-ip:14.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-iq_centralized_management:6.0.0:*:*:*:*:*:*:* OR cpe:/a:f5:big-iq_centralized_management:6.0.1:*:*:*:*:*:*:* OR cpe:/a:f5:iworkflow:2.2.0:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
f5 big-ip access policy manager *
f5 big-ip access policy manager *
f5 big-ip access policy manager *
f5 big-ip access policy manager 14.0.0
f5 big-ip advanced firewall manager *
f5 big-ip advanced firewall manager *
f5 big-ip advanced firewall manager *
f5 big-ip advanced firewall manager 14.0.0
f5 big-ip analytics *
f5 big-ip analytics *
f5 big-ip analytics *
f5 big-ip analytics 14.0.0
f5 big-ip application acceleration manager *
f5 big-ip application acceleration manager *
f5 big-ip application acceleration manager *
f5 big-ip application acceleration manager 14.0.0
f5 big-ip application security manager *
f5 big-ip application security manager *
f5 big-ip application security manager *
f5 big-ip application security manager 14.0.0
f5 big-ip domain name system *
f5 big-ip domain name system *
f5 big-ip domain name system *
f5 big-ip domain name system 14.0.0
f5 big-ip edge gateway *
f5 big-ip edge gateway *
f5 big-ip edge gateway *
f5 big-ip edge gateway 14.0.0
f5 big-ip fraud protection service *
f5 big-ip fraud protection service *
f5 big-ip fraud protection service *
f5 big-ip fraud protection service 14.0.0
f5 big-ip global traffic manager *
f5 big-ip global traffic manager *
f5 big-ip global traffic manager *
f5 big-ip global traffic manager 14.0.0
f5 big-ip link controller *
f5 big-ip link controller *
f5 big-ip link controller *
f5 big-ip link controller 14.0.0
f5 big-ip local traffic manager *
f5 big-ip local traffic manager *
f5 big-ip local traffic manager *
f5 big-ip local traffic manager 14.0.0
f5 big-ip policy enforcement manager *
f5 big-ip policy enforcement manager *
f5 big-ip policy enforcement manager *
f5 big-ip policy enforcement manager 14.0.0
f5 big-ip webaccelerator *
f5 big-ip webaccelerator *
f5 big-ip webaccelerator *
f5 big-ip webaccelerator 14.0.0
f5 enterprise manager 3.1.1
f5 big-iq centralized management 4.6.0
f5 big-iq centralized management *
f5 big-iq centralized management *
f5 iworkflow *
f5 enterprise manager 3.1.1
f5 big-ip 11.2.1
f5 big-ip 12.1.0
f5 big-ip 13.0.0
f5 big-iq centralized management 5.0.0
f5 big-iq centralized management 5.4.0
f5 big-iq centralized management 4.6.0
f5 iworkflow 2.3.0
f5 big-ip 12.1.3.7
f5 big-ip 11.6.3
f5 big-ip 13.1.1
f5 big-ip 14.0.0
f5 big-iq centralized management 6.0.0
f5 big-iq centralized management 6.0.1
f5 iworkflow 2.2.0