| Title | 複数の F5 製品における重要な情報を取得される脆弱性 |
|---|---|
| Summary | 複数の F5 製品は、Amazon Web Services (AWS)、Azure または Verizon クラウドサービス環境でクラウドイメージが展開される場合、資格情報および鍵を適切に再生成しないため、重要な情報を取得される、またはサービス運用妨害 (中断) 状態にされる脆弱性が存在します。 |
| Possible impacts | 攻撃者により、Target Instance 設定を利用されることで、重要な情報を取得される、またはサービス運用妨害 (中断) 状態にされる可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | April 11, 2016, midnight |
| Registration Date | April 26, 2016, 4:45 p.m. |
| Last Update | April 26, 2016, 4:45 p.m. |
| CVSS3.0 : 重要 | |
| Score | 7.4 |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H |
| CVSS2.0 : 警告 | |
| Score | 4 |
|---|---|
| Vector | AV:N/AC:H/Au:N/C:P/I:N/A:P |
| F5 Networks |
| BIG-IP Access Policy Manager (APM) |
| BIG-IP Advanced Firewall Manager (AFM) |
| BIG-IP Analytics |
| BIG-IP Application Acceleration Manager (AAM) |
| BIG-IP Application Security Manager (ASM) |
| BIG-IP Domain Name System (DNS) |
| BIG-IP Edge Gateway |
| BIG-IP Global Traffic Manager (GTM) |
| BIG-IP Link Controller |
| BIG-IP Local Traffic Manager (LTM) |
| BIG-IP Policy Enforcement Manager (PEM) |
| BIG-IP Protocol Security Module (PSM) |
| BIG-IP WAN Optimization Manager (WOM) |
| BIG-IP WebAccelerator |
| BIG-IQ Application Delivery Controller (ADC) |
| BIG-IQ Cloud |
| BIG-IQ Device |
| BIG-IQ Security |
| No | Changed Details | Date of change |
|---|---|---|
| 0 | [2016年04月26日] 掲載 |
Feb. 17, 2018, 10:37 a.m. |
| Summary | F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, 11.6.0 before build 6.204.442, and 12.0.0 before build 1.14.628; BIG-IP AAM 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, 11.6.0 before build 6.204.442, and 12.0.0 before build 1.14.628; BIG-IP DNS 12.0.0 before build 1.14.628; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.3.0; BIG-IP GTM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, and 11.6.0 before build 6.204.442; BIG-IP PSM 11.3.x and 11.4.x before 11.4.1 build 685-HF10; BIG-IQ Cloud, Device, and Security 4.2.0 through 4.5.0; and BIG-IQ ADC 4.5.0 do not properly regenerate certificates and keys when deploying cloud images in Amazon Web Services (AWS), Azure or Verizon cloud services environments, which allows attackers to obtain sensitive information or cause a denial of service (disruption) by leveraging a target instance configuration. |
|---|---|
| Publication Date | April 14, 2016, 1:59 a.m. |
| Registration Date | Jan. 26, 2021, 2:08 p.m. |
| Last Update | Nov. 21, 2024, 11:47 a.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:f5:big-iq_security:4.3.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-iq_security:4.4.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-iq_security:4.2.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-iq_security:4.5.0:*:*:*:*:*:*:* | |||||
| Configuration2 | or higher | or less | more than | less than | |
| cpe:2.3:a:f5:big-ip_webaccelerator:11.3.0:*:*:*:*:*:*:* | |||||
| Configuration3 | or higher | or less | more than | less than | |
| cpe:2.3:a:f5:big-ip_application_security_manager:11.5.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_application_security_manager:11.6.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_application_security_manager:11.4.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_application_security_manager:11.4.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_application_security_manager:11.5.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_application_security_manager:11.3.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_application_security_manager:11.5.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_application_security_manager:11.5.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_application_security_manager:12.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_application_security_manager:11.5.2:*:*:*:*:*:*:* | |||||
| Configuration4 | or higher | or less | more than | less than | |
| cpe:2.3:a:f5:big-ip_access_policy_manager:11.5.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_access_policy_manager:11.5.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_access_policy_manager:12.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_access_policy_manager:11.5.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_access_policy_manager:11.5.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_access_policy_manager:11.4.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_access_policy_manager:11.5.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_access_policy_manager:11.3.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_access_policy_manager:11.6.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_access_policy_manager:11.4.1:*:*:*:*:*:*:* | |||||
| Configuration5 | or higher | or less | more than | less than | |
| cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.4.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.4.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.3.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.6.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.1:*:*:*:*:*:*:* | |||||
| Configuration6 | or higher | or less | more than | less than | |
| cpe:2.3:a:f5:big-iq_cloud:4.2.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-iq_cloud:4.3.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-iq_cloud:4.4.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-iq_cloud:4.5.0:*:*:*:*:*:*:* | |||||
| Configuration7 | or higher | or less | more than | less than | |
| cpe:2.3:a:f5:big-iq_application_delivery_controller:4.5.0:*:*:*:*:*:*:* | |||||
| Configuration8 | or higher | or less | more than | less than | |
| cpe:2.3:a:f5:big-ip_global_traffic_manager:11.4.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_global_traffic_manager:11.3.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_global_traffic_manager:11.5.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_global_traffic_manager:11.5.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_global_traffic_manager:11.6.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_global_traffic_manager:11.4.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_global_traffic_manager:11.5.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_global_traffic_manager:11.5.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_global_traffic_manager:11.5.3:*:*:*:*:*:*:* | |||||
| Configuration9 | or higher | or less | more than | less than | |
| cpe:2.3:a:f5:big-ip_local_traffic_manager:12.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_local_traffic_manager:11.3.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_local_traffic_manager:11.4.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_local_traffic_manager:11.6.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_local_traffic_manager:11.4.0:*:*:*:*:*:*:* | |||||
| Configuration10 | or higher | or less | more than | less than | |
| cpe:2.3:a:f5:big-iq_device:4.2.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-iq_device:4.5.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-iq_device:4.4.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-iq_device:4.3.0:*:*:*:*:*:*:* | |||||
| Configuration11 | or higher | or less | more than | less than | |
| cpe:2.3:a:f5:big-ip_edge_gateway:11.3.0:*:*:*:*:*:*:* | |||||
| Configuration12 | or higher | or less | more than | less than | |
| cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.5.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_application_acceleration_manager:12.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.4.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.5.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.5.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.5.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.6.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.5.0:*:*:*:*:*:*:* | |||||
| Configuration13 | or higher | or less | more than | less than | |
| cpe:2.3:a:f5:big-ip_wan_optimization_manager:11.3.0:*:*:*:*:*:*:* | |||||
| Configuration14 | or higher | or less | more than | less than | |
| cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.5.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.3.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.5.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.6.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.4.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.5.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.5.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_advanced_firewall_manager:12.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.5.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.4.0:*:*:*:*:*:*:* | |||||
| Configuration15 | or higher | or less | more than | less than | |
| cpe:2.3:a:f5:big-ip_link_controller:11.4.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_link_controller:11.5.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_link_controller:11.5.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_link_controller:11.5.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_link_controller:11.4.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_link_controller:11.5.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_link_controller:11.6.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_link_controller:11.5.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_link_controller:12.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_link_controller:11.3.0:*:*:*:*:*:*:* | |||||
| Configuration16 | or higher | or less | more than | less than | |
| cpe:2.3:a:f5:big-ip_protocol_security_module:11.4.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_protocol_security_module:11.3.0:*:*:*:*:*:*:* | |||||
| Configuration17 | or higher | or less | more than | less than | |
| cpe:2.3:a:f5:big-ip_analytics:11.4.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_analytics:11.6.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_analytics:11.3.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_analytics:11.5.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_analytics:11.5.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_analytics:12.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_analytics:11.5.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_analytics:11.4.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_analytics:11.5.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:f5:big-ip_analytics:11.5.0:*:*:*:*:*:*:* | |||||
| Configuration18 | or higher | or less | more than | less than | |
| cpe:2.3:a:f5:big-ip_domain_name_system:12.0.0:*:*:*:*:*:*:* | |||||