CVE-2019-6679 vulnerability in F5 Networks Products
Published on December 23, 2019
On BIG-IP versions 15.0.0-15.0.1, 14.1.0.2-14.1.2.2, 14.0.0.5-14.0.1, 13.1.1.5-13.1.3.1, 12.1.4.1-12.1.5, 11.6.4-11.6.5, and 11.5.9-11.5.10, the access controls implemented by scp.whitelist and scp.blacklist are not properly enforced for paths that are symlinks. This allows authenticated users with SCP access to overwrite certain configuration files that would otherwise be restricted.
Products Associated with CVE-2019-6679
Want to know whenever a new CVE is published for F5 Networks products? stack.watch will email you.
Affected Versions
F5 BIG-IP:- Version 15.0.0-15.0.1 is affected.
- Version 14.1.0.2-14.1.2.2 is affected.
- Version 14.0.0.5-14.0.1 is affected.
- Version 13.1.1.5-13.1.3.1 is affected.
- Version 12.1.4.1-12.1.5 is affected.
- Version 11.6.4-11.6.5 is affected.
- Version 11.5.9-11.5.10 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.