Vulnerability Details CVE-2017-6165
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 11.6.1 HF1, and 12.0.0 through 12.1.2 on VIPRION platforms only, the script which synchronizes SafeNet External Network HSM configuration elements between blades in a clustered deployment will log the HSM partition password in cleartext to the "/var/log/ltm" log file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.021
EPSS Ranking 82.9%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 5.0
Products affected by CVE-2017-6165
-
cpe:2.3:a:f5:big-ip_access_policy_manager:11.5.1
-
cpe:2.3:a:f5:big-ip_access_policy_manager:11.5.2
-
cpe:2.3:a:f5:big-ip_access_policy_manager:11.5.3
-
cpe:2.3:a:f5:big-ip_access_policy_manager:11.5.4
-
cpe:2.3:a:f5:big-ip_access_policy_manager:11.6.0
-
cpe:2.3:a:f5:big-ip_access_policy_manager:11.6.1
-
cpe:2.3:a:f5:big-ip_access_policy_manager:12.0.0
-
cpe:2.3:a:f5:big-ip_access_policy_manager:12.1.0
-
cpe:2.3:a:f5:big-ip_access_policy_manager:12.1.1
-
cpe:2.3:a:f5:big-ip_access_policy_manager:12.1.2
-
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.5.1
-
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.5.2
-
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.5.3
-
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.5.4
-
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.6.0
-
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.6.1
-
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:12.0.0
-
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:12.1.0
-
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:12.1.1
-
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:12.1.2
-
cpe:2.3:a:f5:big-ip_analytics:11.5.1
-
cpe:2.3:a:f5:big-ip_analytics:11.5.2
-
cpe:2.3:a:f5:big-ip_analytics:11.5.3
-
cpe:2.3:a:f5:big-ip_analytics:11.5.4
-
cpe:2.3:a:f5:big-ip_analytics:11.6.0
-
cpe:2.3:a:f5:big-ip_analytics:11.6.1
-
cpe:2.3:a:f5:big-ip_analytics:12.0.0
-
cpe:2.3:a:f5:big-ip_analytics:12.1.0
-
cpe:2.3:a:f5:big-ip_analytics:12.1.1
-
cpe:2.3:a:f5:big-ip_analytics:12.2.0
-
cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.5.1
-
cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.5.2
-
cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.5.3
-
cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.5.4
-
cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.6.0
-
cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.6.1
-
cpe:2.3:a:f5:big-ip_application_acceleration_manager:12.0.0
-
cpe:2.3:a:f5:big-ip_application_acceleration_manager:12.1.0
-
cpe:2.3:a:f5:big-ip_application_acceleration_manager:12.1.1
-
cpe:2.3:a:f5:big-ip_application_acceleration_manager:12.1.2
-
cpe:2.3:a:f5:big-ip_application_security_manager:11.5.1
-
cpe:2.3:a:f5:big-ip_application_security_manager:11.5.2
-
cpe:2.3:a:f5:big-ip_application_security_manager:11.5.3
-
cpe:2.3:a:f5:big-ip_application_security_manager:11.5.4
-
cpe:2.3:a:f5:big-ip_application_security_manager:11.6.0
-
cpe:2.3:a:f5:big-ip_application_security_manager:11.6.1
-
cpe:2.3:a:f5:big-ip_application_security_manager:12.0.0
-
cpe:2.3:a:f5:big-ip_application_security_manager:12.1.0
-
cpe:2.3:a:f5:big-ip_application_security_manager:12.1.1
-
cpe:2.3:a:f5:big-ip_application_security_manager:12.1.2
-
cpe:2.3:a:f5:big-ip_domain_name_system:11.5.1
-
cpe:2.3:a:f5:big-ip_domain_name_system:11.5.2
-
cpe:2.3:a:f5:big-ip_domain_name_system:11.5.3
-
cpe:2.3:a:f5:big-ip_domain_name_system:11.5.4
-
cpe:2.3:a:f5:big-ip_domain_name_system:11.6.0
-
cpe:2.3:a:f5:big-ip_domain_name_system:11.6.1
-
cpe:2.3:a:f5:big-ip_domain_name_system:12.0.0
-
cpe:2.3:a:f5:big-ip_domain_name_system:12.1.0
-
cpe:2.3:a:f5:big-ip_domain_name_system:12.1.1
-
cpe:2.3:a:f5:big-ip_domain_name_system:12.1.2
-
cpe:2.3:a:f5:big-ip_global_traffic_manager:11.5.1
-
cpe:2.3:a:f5:big-ip_global_traffic_manager:11.5.2
-
cpe:2.3:a:f5:big-ip_global_traffic_manager:11.5.3
-
cpe:2.3:a:f5:big-ip_global_traffic_manager:11.5.4
-
cpe:2.3:a:f5:big-ip_global_traffic_manager:11.6.0
-
cpe:2.3:a:f5:big-ip_global_traffic_manager:11.6.1
-
cpe:2.3:a:f5:big-ip_global_traffic_manager:12.0.0
-
cpe:2.3:a:f5:big-ip_global_traffic_manager:12.1.0
-
cpe:2.3:a:f5:big-ip_global_traffic_manager:12.1.1
-
cpe:2.3:a:f5:big-ip_global_traffic_manager:12.1.2
-
cpe:2.3:a:f5:big-ip_link_controller:11.5.1
-
cpe:2.3:a:f5:big-ip_link_controller:11.5.2
-
cpe:2.3:a:f5:big-ip_link_controller:11.5.3
-
cpe:2.3:a:f5:big-ip_link_controller:11.5.4
-
cpe:2.3:a:f5:big-ip_link_controller:11.6.0
-
cpe:2.3:a:f5:big-ip_link_controller:11.6.1
-
cpe:2.3:a:f5:big-ip_link_controller:12.0.0
-
cpe:2.3:a:f5:big-ip_link_controller:12.1.0
-
cpe:2.3:a:f5:big-ip_link_controller:12.1.1
-
cpe:2.3:a:f5:big-ip_link_controller:12.1.2
-
cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.1
-
cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.2
-
cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.3
-
cpe:2.3:a:f5:big-ip_local_traffic_manager:11.5.4
-
cpe:2.3:a:f5:big-ip_local_traffic_manager:11.6.0
-
cpe:2.3:a:f5:big-ip_local_traffic_manager:11.6.1
-
cpe:2.3:a:f5:big-ip_local_traffic_manager:12.0.0
-
cpe:2.3:a:f5:big-ip_local_traffic_manager:12.1.0
-
cpe:2.3:a:f5:big-ip_local_traffic_manager:12.1.1
-
cpe:2.3:a:f5:big-ip_local_traffic_manager:12.1.2
-
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.1
-
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.2
-
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.3
-
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.5.4
-
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.6.0
-
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.6.1
-
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.0.0
-
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.1.0
-
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.1.1
-
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:12.1.2
-
cpe:2.3:a:f5:big-ip_websafe:11.5.1
-
cpe:2.3:a:f5:big-ip_websafe:11.5.2
-
cpe:2.3:a:f5:big-ip_websafe:11.5.3
-
cpe:2.3:a:f5:big-ip_websafe:11.5.4
-
cpe:2.3:a:f5:big-ip_websafe:11.6.0
-
cpe:2.3:a:f5:big-ip_websafe:11.6.1
-
cpe:2.3:a:f5:big-ip_websafe:12.0.0
-
cpe:2.3:a:f5:big-ip_websafe:12.1.0
-
cpe:2.3:a:f5:big-ip_websafe:12.1.1
-
cpe:2.3:a:f5:big-ip_websafe:12.1.2
-
cpe:2.3:h:f5:viprion_application_delivery_controller:-