In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, authenticated users with the ability to upload files (via scp, for example) can escalate their privileges to allow root shell access from within the TMOS Shell (tmsh) interface. The tmsh interface allows users to execute a secondary program via tools like sftp or scp.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
Configuration 8 (hide)
|
Configuration 9 (hide)
|
Configuration 10 (hide)
|
Configuration 11 (hide)
|
Configuration 12 (hide)
|
Configuration 13 (hide)
|
Configuration 14 (hide)
|
Configuration 15 (hide)
|
History
No history.
Information
Published : 2019-07-01 21:15
Updated : 2023-11-07 03:13
NVD link : CVE-2019-6642
Mitre link : CVE-2019-6642
CVE.ORG link : CVE-2019-6642
JSON object : View
Products Affected
f5
- big-ip_local_traffic_manager
- enterprise_manager
- iworkflow
- big-ip_analytics
- big-ip_advanced_firewall_manager
- big-ip_fraud_protection_service
- big-ip_webaccelerator
- big-ip_global_traffic_manager
- big-ip_edge_gateway
- big-ip_application_acceleration_manager
- big-ip_domain_name_system
- big-ip_application_security_manager
- big-iq_centralized_management
- big-ip_policy_enforcement_manager
- big-ip_link_controller
- big-ip_access_policy_manager
CWE