CVE-2016-2084
Last modified
CVE-2016-2084 is a vulnerability of currently unknown severity. F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, 11.6.0 before build 6.204.442, and 12.0.0 before build 1.14.628; BIG-IP AAM 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, 11.6.0 before build 6.204.442, and 12.0.0 before build 1.14.628; BIG-IP DNS 12.0.0 before build 1.14.628; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.3.0; BIG-IP GTM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, and 11.6.0 before build 6.204.442; BIG-IP PSM 11.3.x and 11.4.x before 11.4.1 build 685-HF10; BIG-IQ Cloud, Device, and Security 4.2.0 through 4.5.0; and BIG-IQ ADC 4.5.0 do not properly regenerate certificates and keys when deploying cloud images in Amazon Web Services (AWS), Azure or Verizon cloud services environments, which allows attackers to obtain sensitive information or cause a denial of service (disruption) by leveraging a target instance configuration.. EPSS estimates a 0.79% chance of exploitation in the next 30 days.
Description
F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, 11.6.0 before build 6.204.442, and 12.0.0 before build 1.14.628; BIG-IP AAM 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, 11.6.0 before build 6.204.442, and 12.0.0 before build 1.14.628; BIG-IP DNS 12.0.0 before build 1.14.628; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.3.0; BIG-IP GTM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, and 11.6.0 before build 6.204.442; BIG-IP PSM 11.3.x and 11.4.x before 11.4.1 build 685-HF10; BIG-IQ Cloud, Device, and Security 4.2.0 through 4.5.0; and BIG-IQ ADC 4.5.0 do not properly regenerate certificates and keys when deploying cloud images in Amazon Web Services (AWS), Azure or Verizon cloud services environments, which allows attackers to obtain sensitive information or cause a denial of service (disruption) by leveraging a target instance configuration.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Iq Security | 4.2.0 |
| F5 | Big-Iq Security | 4.3.0 |
| F5 | Big-Iq Security | 4.4.0 |
| F5 | Big-Iq Security | 4.5.0 |
| F5 | Big-Ip Webaccelerator | 11.3.0 |
| F5 | Big-Ip Application Security Manager | 11.3.0 |
| F5 | Big-Ip Application Security Manager | 11.4.0 |
| F5 | Big-Ip Application Security Manager | 11.4.1 |
| F5 | Big-Ip Application Security Manager | 11.5.0 |
| F5 | Big-Ip Application Security Manager | 11.5.1 |
| F5 | Big-Ip Application Security Manager | 11.5.2 |
| F5 | Big-Ip Application Security Manager | 11.5.3 |
| F5 | Big-Ip Application Security Manager | 11.5.4 |
| F5 | Big-Ip Application Security Manager | 11.6.0 |
| F5 | Big-Ip Application Security Manager | 12.0.0 |
| F5 | Big-Ip Access Policy Manager | 11.3.0 |
| F5 | Big-Ip Access Policy Manager | 11.4.0 |
| F5 | Big-Ip Access Policy Manager | 11.4.1 |
| F5 | Big-Ip Access Policy Manager | 11.5.0 |
| F5 | Big-Ip Access Policy Manager | 11.5.1 |
| F5 | Big-Ip Access Policy Manager | 11.5.2 |
| F5 | Big-Ip Access Policy Manager | 11.5.3 |
| F5 | Big-Ip Access Policy Manager | 11.5.4 |
| F5 | Big-Ip Access Policy Manager | 11.6.0 |
| F5 | Big-Ip Access Policy Manager | 12.0.0 |
| F5 | Big-Ip Policy Enforcement Manager | 11.3.0 |
| F5 | Big-Ip Policy Enforcement Manager | 11.4.0 |
| F5 | Big-Ip Policy Enforcement Manager | 11.4.1 |
| F5 | Big-Ip Policy Enforcement Manager | 11.5.0 |
| F5 | Big-Ip Policy Enforcement Manager | 11.5.1 |
| F5 | Big-Ip Policy Enforcement Manager | 11.5.2 |
| F5 | Big-Ip Policy Enforcement Manager | 11.5.3 |
| F5 | Big-Ip Policy Enforcement Manager | 11.5.4 |
| F5 | Big-Ip Policy Enforcement Manager | 11.6.0 |
| F5 | Big-Ip Policy Enforcement Manager | 12.0.0 |
| F5 | Big-Iq Cloud | 4.2.0 |
| F5 | Big-Iq Cloud | 4.3.0 |
| F5 | Big-Iq Cloud | 4.4.0 |
| F5 | Big-Iq Cloud | 4.5.0 |
| F5 | Big-Iq Application Delivery Controller | 4.5.0 |
| F5 | Big-Ip Global Traffic Manager | 11.3.0 |
| F5 | Big-Ip Global Traffic Manager | 11.4.0 |
| F5 | Big-Ip Global Traffic Manager | 11.4.1 |
| F5 | Big-Ip Global Traffic Manager | 11.5.0 |
| F5 | Big-Ip Global Traffic Manager | 11.5.1 |
| F5 | Big-Ip Global Traffic Manager | 11.5.2 |
| F5 | Big-Ip Global Traffic Manager | 11.5.3 |
| F5 | Big-Ip Global Traffic Manager | 11.5.4 |
| F5 | Big-Ip Global Traffic Manager | 11.6.0 |
| F5 | Big-Ip Local Traffic Manager | 11.3.0 |
Showing 50 of 106 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-2084?
How severe is CVE-2016-2084?
How do I fix CVE-2016-2084?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-2078Cross-site scripting (XSS) vulnerability in the Web Client i…
- CVE-2016-2079VMware NSX Edge 6.1 before 6.1.7 and 6.2 before 6.2.3 and vC…
- CVE-2016-2080Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-2081Cross-site scripting (XSS) vulnerability in VMware vRealize …
- CVE-2016-2082Cross-site request forgery (CSRF) vulnerability in VMware vR…
- CVE-2016-2083Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-2085The evm_verify_hmac function in security/integrity/evm/evm_m…
- CVE-2016-2086Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x be…
- CVE-2016-2087Directory traversal vulnerability in the client in HexChat 2…
- CVE-2016-2088resolver.c in named in ISC BIND 9.10.x before 9.10.3-P4, whe…
- CVE-2016-2089The jas_matrix_clip function in jas_seq.c in JasPer 1.900.1 …
- CVE-2016-2090Off-by-one vulnerability in the fgetwln function in libbsd b…9.8
Are you affected by CVE-2016-2084?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
