Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6vq9-584m-2q8f

Опубликовано: 10 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker with the ability to intercept traffic to impersonate the SPK Secure Shell (SSH) server on those containers. This is only exposed when ssh debug is enabled.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker with the ability to intercept traffic to impersonate the SPK Secure Shell (SSH) server on those containers. This is only exposed when ssh debug is enabled.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

EPSS

Процентиль: 68%
0.00572
Низкий

7.4 High

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 7.4
nvd
больше 2 лет назад

The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker with the ability to intercept traffic to impersonate the SPK Secure Shell (SSH) server on those containers. This is only exposed when ssh debug is enabled.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 7.4
fstec
больше 2 лет назад

Уязвимость модуля управления трафиком (Traffic Management Module) средства контроля доступа и удаленной аутентификации BIG-IP, позволяющая нарушителю выдать себя за сервер SPK Secure Shell (SSH)

EPSS

Процентиль: 68%
0.00572
Низкий

7.4 High

CVSS3

Дефекты

CWE-798