CVE-2012-1493
Last modified
CVE-2012-1493 is a vulnerability of currently unknown severity. F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.. EPSS estimates a 63.08% chance of exploitation in the next 30 days.
Description
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| F5 | Big-Ip Application Security Manager | 9.2.0 | — |
| F5 | Big-Ip Application Security Manager | 9.4.4 | — |
| F5 | Big-Ip Application Security Manager | 9.4.5 | — |
| F5 | Big-Ip Application Security Manager | 9.4.6 | — |
| F5 | Big-Ip Application Security Manager | 9.4.7 | — |
| F5 | Big-Ip Application Security Manager | 9.4.8 | — |
| F5 | Big-Ip Application Security Manager | 10.0.0 | — |
| F5 | Big-Ip Application Security Manager | 10.0.1 | — |
| F5 | Big-Ip Application Security Manager | 10.2.3 | Hf1 |
| F5 | Big-Ip Application Security Manager | 11.0.0 | — |
| F5 | Big-Ip Application Security Manager | 11.1.0 | — |
| F5 | Big-Ip Global Traffic Manager | All versions | — |
| F5 | Big-Ip Global Traffic Manager | 9.2.2 | — |
| F5 | Big-Ip Global Traffic Manager | 9.4.8 | Hf4 |
| F5 | Big-Ip Global Traffic Manager | 10.0.0 | — |
| F5 | Big-Ip Global Traffic Manager | 10.2.3 | Hf1 |
| F5 | Big-Ip Global Traffic Manager | 11.0.0 | — |
| F5 | Big-Ip Global Traffic Manager | 11.1.0 | — |
| F5 | Big-Ip Local Traffic Manager | All versions | — |
| F5 | Big-Ip Local Traffic Manager | 9.0.0 | — |
| F5 | Big-Ip Local Traffic Manager | 9.4.8 | Hf4 |
| F5 | Big-Ip Local Traffic Manager | 10.0.0 | — |
| F5 | Big-Ip Local Traffic Manager | 10.2.3 | Hf1 |
| F5 | Big-Ip Local Traffic Manager | 11.0.0 | — |
| F5 | Big-Ip Local Traffic Manager | 11.1.0 | — |
| F5 | Tmos | All versions | — |
| F5 | Tmos | 2.0 | — |
| F5 | Tmos | 4.0 | — |
| F5 | Tmos | 4.2 | — |
| F5 | Tmos | 4.3 | — |
| F5 | Tmos | 4.4 | — |
| F5 | Tmos | 4.5 | — |
| F5 | Tmos | 4.5.6 | — |
| F5 | Tmos | 4.5.9 | — |
| F5 | Tmos | 4.5.10 | — |
| F5 | Tmos | 4.5.11 | — |
| F5 | Tmos | 4.5.12 | — |
| F5 | Tmos | 4.6 | — |
| F5 | Tmos | 4.6.2 | — |
| F5 | Tmos | 9.0 | — |
| F5 | Tmos | 9.0.1 | — |
| F5 | Tmos | 9.0.2 | — |
| F5 | Tmos | 9.0.3 | — |
| F5 | Tmos | 9.0.4 | — |
| F5 | Tmos | 9.0.5 | — |
| F5 | Tmos | 9.1 | — |
| F5 | Tmos | 9.1.1 | — |
| F5 | Tmos | 9.1.2 | — |
| F5 | Tmos | 9.1.3 | — |
| F5 | Tmos | 9.2 | — |
Showing 50 of 97 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-1493?
How severe is CVE-2012-1493?
How do I fix CVE-2012-1493?
Are you affected by CVE-2012-1493?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
