On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, under certain circumstances, attackers can decrypt configuration items that are encrypted because the vCMP configuration unit key is generated with insufficient randomness. The attack prerequisite is direct access to encrypted configuration and/or UCS files.
References
Link Resource
http://www.securityfocus.com/bid/109112 Third Party Advisory VDB Entry
https://support.f5.com/csp/article/K01413496 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: f5

Published: 2019-07-03T18:06:01

Updated: 2019-07-11T08:06:02

Reserved: 2019-01-22T00:00:00


Link: CVE-2019-6632

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-07-03T19:15:12.970

Modified: 2021-07-21T11:39:23.747


Link: CVE-2019-6632

JSON object: View

cve-icon Redhat Information

No data.

CWE