← All CVEs

CVE-2012-1493

high · 7.8

F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.

7.8
CVSS
63.1%
EPSS (exploit prob.)
99th
EPSS percentile
2012-07-09
Published

AV:N/AC:L/Au:N/C:C/I:N/A:N

Weaknesses

CWE-255

Affected products

VendorProductAffected versions
f5big-ip_application_security_manager9.2.0
f5big-ip_application_security_manager9.2.0
f5big-ip_application_security_manager9.4.4
f5big-ip_application_security_manager9.4.5
f5big-ip_application_security_manager9.4.6
f5big-ip_application_security_manager9.4.7
f5big-ip_application_security_manager9.4.8
f5big-ip_application_security_manager10.0.0
f5big-ip_application_security_manager10.0.1
f5big-ip_application_security_manager10.2.3
f5big-ip_application_security_manager11.0.0
f5big-ip_application_security_manager11.0.0
f5big-ip_application_security_manager11.1.0
f5big-ip_application_security_manager11.1.0
f5big-ip_global_traffic_managerall versions
f5big-ip_global_traffic_manager9.2.2
f5big-ip_global_traffic_manager9.4.8
f5big-ip_global_traffic_manager10.0.0
f5big-ip_global_traffic_manager10.2.3
f5big-ip_global_traffic_manager11.0.0
f5big-ip_global_traffic_manager11.0.0
f5big-ip_global_traffic_manager11.1.0
f5big-ip_global_traffic_manager11.1.0
f5big-ip_local_traffic_managerall versions
f5big-ip_local_traffic_manager9.0.0
f5big-ip_local_traffic_manager9.4.8
f5big-ip_local_traffic_manager10.0.0
f5big-ip_local_traffic_manager10.2.3
f5big-ip_local_traffic_manager11.0.0
f5big-ip_local_traffic_manager11.0.0
f5big-ip_local_traffic_manager11.1.0
f5big-ip_local_traffic_manager11.1.0
f5tmosall versions
f5tmos2.0
f5tmos4.0
f5tmos4.2
f5tmos4.3
f5tmos4.4
f5tmos4.5
f5tmos4.5.6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-1493