CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2016-5700 F5 BIG-IP ASM HTTP Explicit Proxy or SOCKS Profile Remote Code Execution Vulnerability (SOL35520031)

2016年11月1日 2049点热度 0人点赞 0条评论

漏洞类别:Local

漏洞等级:

漏洞信息

BIG-IP virtual servers with a configuration using the HTTP Explicit Proxy functionality and/or SOCKS profile are vulnerable to an unauthenticated, remote attack that allows modification of BIG-IP system configuration, extraction of sensitive system files, and/or possible remote command execution on the BIG-IP system.

Affected Versions:
BIG-IP ASM 12.1.0 - 12.1.0 HF1
BIG-IP ASM 12.0.0 - 12.0.0 HF3
BIG-IP ASM 11.6.1
BIG-IP ASM 11.6.0 - 11.6.0 HF7
BIG-IP ASM 11.5.2 - 11.5.4 HF1
BIG-IP ASM 11.5.0 - 11.5.1 HF10

NOTE: Only virtual servers with configurations using the HTTP Explicit Proxy functionality and/or SOCKS profile are vulnerable.

漏洞危害

Successful exploitation allows an unauthenticated, remote attacker to modify BIG-IP system configuration, extract sensitive system files, or execute arbitrary code on the targeted BIG-IP system.

解决方案

Customers are advised to refer to SOL35520031 for updates pertaining to this vulnerability.

Patch:
Following are links for downloading patches to fix the vulnerabilities:

SOL35520031

0day

标签: 暂无
最后更新:2016年11月1日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me