Critical severity9.8NVD Advisory· Published Oct 20, 2017· Updated Jun 17, 2026
CVE-2017-6165
CVE-2017-6165
Description
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 11.6.1 HF1, and 12.0.0 through 12.1.2 on VIPRION platforms only, the script which synchronizes SafeNet External Network HSM configuration elements between blades in a clustered deployment will log the HSM partition password in cleartext to the "/var/log/ltm" log file.
Affected products
2- F5, Inc./Big Ip (ltm, Aam, Afm, Analytics, Apm, Asm, DNS, Edge Gateway, Fps, Gtm, Link Controller, Pem, Webaccelerator)llm-fuzzyRange: 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 11.6.1 HF1, and 12.0.0 through 12.1.2
- Range: 12.0.0 through 12.1.2
Patches
Vulnerability mechanics
References
3- www.securityfocus.com/bid/101543nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1039638nvdThird Party AdvisoryVDB Entry
- support.f5.com/csp/article/K74759095nvdVendor Advisory
News mentions
0No linked articles in our index yet.