CVE-2012-1493
Last modified
CVE-2012-1493 is a vulnerability of currently unknown severity. F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.. EPSS estimates a 63.08% chance of exploitation in the next 30 days.
Description
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| F5 | Big-Ip Application Security Manager | 9.2.0 | — |
| F5 | Big-Ip Application Security Manager | 9.4.4 | — |
| F5 | Big-Ip Application Security Manager | 9.4.5 | — |
| F5 | Big-Ip Application Security Manager | 9.4.6 | — |
| F5 | Big-Ip Application Security Manager | 9.4.7 | — |
| F5 | Big-Ip Application Security Manager | 9.4.8 | — |
| F5 | Big-Ip Application Security Manager | 10.0.0 | — |
| F5 | Big-Ip Application Security Manager | 10.0.1 | — |
| F5 | Big-Ip Application Security Manager | 10.2.3 | Hf1 |
| F5 | Big-Ip Application Security Manager | 11.0.0 | — |
| F5 | Big-Ip Application Security Manager | 11.1.0 | — |
| F5 | Big-Ip Global Traffic Manager | All versions | — |
| F5 | Big-Ip Global Traffic Manager | 9.2.2 | — |
| F5 | Big-Ip Global Traffic Manager | 9.4.8 | Hf4 |
| F5 | Big-Ip Global Traffic Manager | 10.0.0 | — |
| F5 | Big-Ip Global Traffic Manager | 10.2.3 | Hf1 |
| F5 | Big-Ip Global Traffic Manager | 11.0.0 | — |
| F5 | Big-Ip Global Traffic Manager | 11.1.0 | — |
| F5 | Big-Ip Local Traffic Manager | All versions | — |
| F5 | Big-Ip Local Traffic Manager | 9.0.0 | — |
| F5 | Big-Ip Local Traffic Manager | 9.4.8 | Hf4 |
| F5 | Big-Ip Local Traffic Manager | 10.0.0 | — |
| F5 | Big-Ip Local Traffic Manager | 10.2.3 | Hf1 |
| F5 | Big-Ip Local Traffic Manager | 11.0.0 | — |
| F5 | Big-Ip Local Traffic Manager | 11.1.0 | — |
| F5 | Tmos | All versions | — |
| F5 | Tmos | 2.0 | — |
| F5 | Tmos | 4.0 | — |
| F5 | Tmos | 4.2 | — |
| F5 | Tmos | 4.3 | — |
| F5 | Tmos | 4.4 | — |
| F5 | Tmos | 4.5 | — |
| F5 | Tmos | 4.5.6 | — |
| F5 | Tmos | 4.5.9 | — |
| F5 | Tmos | 4.5.10 | — |
| F5 | Tmos | 4.5.11 | — |
| F5 | Tmos | 4.5.12 | — |
| F5 | Tmos | 4.6 | — |
| F5 | Tmos | 4.6.2 | — |
| F5 | Tmos | 9.0 | — |
| F5 | Tmos | 9.0.1 | — |
| F5 | Tmos | 9.0.2 | — |
| F5 | Tmos | 9.0.3 | — |
| F5 | Tmos | 9.0.4 | — |
| F5 | Tmos | 9.0.5 | — |
| F5 | Tmos | 9.1 | — |
| F5 | Tmos | 9.1.1 | — |
| F5 | Tmos | 9.1.2 | — |
| F5 | Tmos | 9.1.3 | — |
| F5 | Tmos | 9.2 | — |
Showing 50 of 97 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-1493?
How severe is CVE-2012-1493?
How do I fix CVE-2012-1493?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-1480Unspecified vulnerability in the Pansi SMS (com.pansi.msg) a…
- CVE-2012-1481Unspecified vulnerability in the Textdroid (com.app.android.…
- CVE-2012-1482Unspecified vulnerability in the TouchPal Contacts (com.coot…
- CVE-2012-1483Unspecified vulnerability in the Message Forwarder (com.gmai…
- CVE-2012-1484Unspecified vulnerability in the WaliSMS CN (cn.com.wali.wal…
- CVE-2012-1485Unspecified vulnerability in the NetFront Life Browser (com.…
- CVE-2012-1495install/index.php in WebCalendar before 1.2.5 allows remote …9.8
- CVE-2012-1496Local file inclusion in WebCalendar before 1.2.5.8.8
- CVE-2012-1497The default configuration of Movable Type before 4.38, 5.0x …
- CVE-2012-1498Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2012-1499The JPEG 2000 codec (jp2.c) in OpenJPEG before 1.5 allows re…
- CVE-2012-1500Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4…5.4
Are you affected by CVE-2012-1493?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
