Vulnerabilities > CVE-2012-1493 - Credentials Management vulnerability in F5 products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Exploit-Db
description F5 BIG-IP SSH Private Key Exposure. CVE-2012-1493. Remote exploit for hardware platform id EDB-ID:19099 last seen 2016-02-02 modified 2012-06-13 published 2012-06-13 reporter metasploit source https://www.exploit-db.com/download/19099/ title F5 BIG-IP - SSH Private Key Exposure description F5 BIG-IP Remote Root Authentication Bypass Vulnerability. CVE-2012-1493. Dos exploit for hardware platform id EDB-ID:19064 last seen 2016-02-02 modified 2012-06-11 published 2012-06-11 reporter Florent Daigniere source https://www.exploit-db.com/download/19064/ title F5 BIG-IP Remote Root Authentication Bypass Vulnerability description F5 BIG-IP Remote Root Authentication Bypass Vulnerability. CVE-2012-1493. Remote exploit for hardware platform id EDB-ID:19091 last seen 2016-02-02 modified 2012-06-12 published 2012-06-12 reporter David Kennedy (ReL1K) source https://www.exploit-db.com/download/19091/ title F5 BIG-IP Remote Root Authentication Bypass Vulnerability
Metasploit
description | F5 ships a public/private key pair on BIG-IP appliances that allows passwordless authentication to any other BIG-IP box. Since the key is easily retrievable, an attacker can use it to gain unauthorized remote access as root. |
id | MSF:EXPLOIT/LINUX/SSH/F5_BIGIP_KNOWN_PRIVKEY |
last seen | 2020-06-10 |
modified | 2020-02-18 |
published | 2012-06-12 |
references | |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/linux/ssh/f5_bigip_known_privkey.rb |
title | F5 BIG-IP SSH Private Key Exposure |
Nessus
NASL family Gain a shell remotely NASL id SSH_STATIC_KEYS.NASL description The SSH server on the remote host accepts a publicly known static SSH private key for authentication. A remote attacker can log in to this host using this publicly known private key. last seen 2020-06-01 modified 2020-06-02 plugin id 73920 published 2014-05-08 reporter This script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/73920 title SSH Static Key Accepted NASL family Gain a shell remotely NASL id F5_ROOT_AUTH_BYPASS.NASL description The remote F5 device has an authentication bypass vulnerability. The SSH private key for the root user is publicly known. A remote, unauthenticated attacker could exploit this to login as root. last seen 2020-06-01 modified 2020-06-02 plugin id 59477 published 2012-06-13 reporter This script is Copyright (C) 2012-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/59477 title F5 Multiple Products Root Authentication Bypass
Packetstorm
data source https://packetstormsecurity.com/files/download/113526/MATTA-2012-002.txt id PACKETSTORM:113526 last seen 2016-12-05 published 2012-06-12 reporter Florent Daigniere source https://packetstormsecurity.com/files/113526/F5-BIG-IP-Remote-Root-Authentication-Bypass.html title F5 BIG-IP Remote Root Authentication Bypass data source https://packetstormsecurity.com/files/download/113577/f5_bigip_known_privkey.rb.txt id PACKETSTORM:113577 last seen 2016-12-05 published 2012-06-12 reporter egypt source https://packetstormsecurity.com/files/113577/F5-BIG-IP-SSH-Private-Key-Exposure.html title F5 BIG-IP SSH Private Key Exposure
Saint
bid | 53897 |
description | F5 BIG-IP SSH private key |
osvdb | 82780 |
title | ssh_bigip |
type | remote |
Seebug
bulletinFamily exploit description No description provided by source. id SSV:73034 last seen 2017-11-19 modified 2014-07-01 published 2014-07-01 reporter Root source https://www.seebug.org/vuldb/ssvid-73034 title F5 BIG-IP Remote Root Authentication Bypass Vulnerability bulletinFamily exploit description No description provided by source. id SSV:60202 last seen 2017-11-19 modified 2012-06-11 published 2012-06-11 reporter Root source https://www.seebug.org/vuldb/ssvid-60202 title F5 BIG-IP remote root authentication bypass Vulnerability(CVE-2012-1493)
References
- https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/ssh/f5_bigip_known_privkey.rb
- http://www.theregister.co.uk/2012/06/13/f5_kit_metasploit_exploit/
- http://support.f5.com/kb/en-us/solutions/public/13000/600/sol13600.html
- https://www.trustmatta.com/advisories/MATTA-2012-002.txt