CVE-2015-4040

EUVD-2015-4068
Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 through 3.1.1 allows remote authenticated users to access arbitrary files in the web root via unspecified vectors.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
f5enterprise_manager
3.0.0
f5enterprise_manager
3.1.0
f5enterprise_manager
3.1.1
f5big-ip_access_policy_manager
𝑥
≤ 11.6.0
f5big-ip_advanced_firewall_manager
𝑥
≤ 11.6.0
f5big-ip_analytics
𝑥
≤ 11.6.0
f5big-ip_application_acceleration_manager
𝑥
≤ 11.6.0
f5big-ip_application_security_manager
𝑥
≤ 11.6.0
f5big-ip_edge_gateway
𝑥
≤ 11.3.0
f5big-ip_global_traffic_manager
𝑥
≤ 11.3.0
f5big-ip_link_controller
𝑥
≤ 11.3.0
f5big-ip_local_traffic_manager
𝑥
≤ 11.6.0
f5big-ip_policy_enforcement_manager
𝑥
≤ 11.3.0
f5big-ip_protocol_security_module
𝑥
≤ 11.3.0
f5big-ip_wan_optimization_manager
𝑥
≤ 11.3.0
f5big-ip_webaccelerator
𝑥
≤ 11.3.0
𝑥
= Vulnerable software versions