CVE-2015-4040

Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 through 3.1.1 allows remote authenticated users to access arbitrary files in the web root via unspecified vectors.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
VendorProductVersion
f5enterprise_manager
3.0.0
f5enterprise_manager
3.1.0
f5enterprise_manager
3.1.1
f5big-ip_access_policy_manager
𝑥
≤ 11.6.0
f5big-ip_advanced_firewall_manager
𝑥
≤ 11.6.0
f5big-ip_analytics
𝑥
≤ 11.6.0
f5big-ip_application_acceleration_manager
𝑥
≤ 11.6.0
f5big-ip_application_security_manager
𝑥
≤ 11.6.0
f5big-ip_edge_gateway
𝑥
≤ 11.3.0
f5big-ip_global_traffic_manager
𝑥
≤ 11.3.0
f5big-ip_link_controller
𝑥
≤ 11.3.0
f5big-ip_local_traffic_manager
𝑥
≤ 11.6.0
f5big-ip_policy_enforcement_manager
𝑥
≤ 11.3.0
f5big-ip_protocol_security_module
𝑥
≤ 11.3.0
f5big-ip_wan_optimization_manager
𝑥
≤ 11.3.0
f5big-ip_webaccelerator
𝑥
≤ 11.3.0
𝑥
= Vulnerable software versions