CVE-2017-0305
Last modified
CVE-2017-0305 is a vulnerability of currently unknown severity. F5 SSL Intercept iApp version 1.5.0 - 1.5.7 is vulnerable to an unauthenticated, remote attack that may allow modification of the BIG-IP system configuration, extraction of sensitive system files, and possible remote command execution on the system when deployed using the Explicit Proxy feature plus SNAT Auto Map option for egress traffic.. EPSS estimates a 3.78% chance of exploitation in the next 30 days.
Description
F5 SSL Intercept iApp version 1.5.0 - 1.5.7 is vulnerable to an unauthenticated, remote attack that may allow modification of the BIG-IP system configuration, extraction of sensitive system files, and possible remote command execution on the system when deployed using the Explicit Proxy feature plus SNAT Auto Map option for egress traffic.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| F5 | Ssl Intercept Iapp | 1.5.0 |
| F5 | Ssl Intercept Iapp | 1.5.7 |
References
- https://support.f5.com/csp/article/K53244431Vendor Advisory
- https://support.f5.com/csp/article/K53244431Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-0305?
How severe is CVE-2017-0305?
How do I fix CVE-2017-0305?
Are you affected by CVE-2017-0305?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
