Unrated severityNVD Advisory· Published Dec 23, 2019· Updated Aug 5, 2024
CVE-2019-19151
CVE-2019-19151
Description
On BIG-IP versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, BIG-IQ versions 7.0.0, 6.0.0-6.1.0, and 5.0.0-5.4.0, iWorkflow version 2.3.0, and Enterprise Manager version 3.1.1, authenticated users granted TMOS Shell (tmsh) privileges are able access objects on the file system which would normally be disallowed by tmsh restrictions. This allows for authenticated, low privileged attackers to access objects on the file system which would not normally be allowed.
Affected products
1- Range: BIG-IP 15.0.0-15.1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- support.f5.com/csp/article/K21711352mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.