CVE-2017-0305
Last modified
CVE-2017-0305 is a vulnerability of currently unknown severity. F5 SSL Intercept iApp version 1.5.0 - 1.5.7 is vulnerable to an unauthenticated, remote attack that may allow modification of the BIG-IP system configuration, extraction of sensitive system files, and possible remote command execution on the system when deployed using the Explicit Proxy feature plus SNAT Auto Map option for egress traffic.. EPSS estimates a 3.78% chance of exploitation in the next 30 days.
Description
F5 SSL Intercept iApp version 1.5.0 - 1.5.7 is vulnerable to an unauthenticated, remote attack that may allow modification of the BIG-IP system configuration, extraction of sensitive system files, and possible remote command execution on the system when deployed using the Explicit Proxy feature plus SNAT Auto Map option for egress traffic.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| F5 | Ssl Intercept Iapp | 1.5.0 |
| F5 | Ssl Intercept Iapp | 1.5.7 |
References
- https://support.f5.com/csp/article/K53244431Vendor Advisory
- https://support.f5.com/csp/article/K53244431Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-0305?
How severe is CVE-2017-0305?
How do I fix CVE-2017-0305?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-0299The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, …
- CVE-2017-0300The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, …
- CVE-2017-0301In F5 BIG-IP APM software versions 11.5.0, 11.5.1, 11.5.2, 1…
- CVE-2017-0302In F5 BIG-IP APM 12.0.0 through 12.1.2 and 13.0.0, an authen…
- CVE-2017-0303In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, L…
- CVE-2017-0304A SQL injection vulnerability exists in the BIG-IP AFM manag…
- CVE-2017-0306An elevation of privilege vulnerability in the NVIDIA GPU dr…
- CVE-2017-0307An elevation of privilege vulnerability in the NVIDIA GPU dr…
- CVE-2017-0308All versions of NVIDIA Windows GPU Display Driver contain a …
- CVE-2017-0309All versions of NVIDIA GPU Display Driver contain a vulnerab…
- CVE-2017-0310All versions of NVIDIA GPU Display Driver contain a vulnerab…
- CVE-2017-0311NVIDIA GPU Display Driver R378 contains a vulnerability in t…
Are you affected by CVE-2017-0305?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
