CVE-2019-6644
high-risk
Published 2019-09-04
Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, and 12.1.0-12.1.4 BIG-IP will bind a debug nodejs process to all interfaces when invoked. This may expose the process to unauthorized users if the plugin is left in debug mode and the port is accessible.
Do I need to act?
-
0.79% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.4/10
Critical
NETWORK
/ LOW complexity
Affected Products (20)
Affected Vendors
References (2)
Vendor Advisory
https://support.f5.com/csp/article/K75532331
Vendor Advisory
https://support.f5.com/csp/article/K75532331
58
/ 100
high-risk
Severity
31/34 · Critical
Exploitability
3/34 · Minimal
Exposure
24/34 · High