CVE-2015-4040
mediumCVSS v3 Base Score
4.0
AV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS Score
6.8%
Exploitation probability in 30 days
Top 9% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
P
Integrity
None
Availability
None
Vulnerability Report
Generated by CyberWatcher
Description
Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 through 3.1.1 allows remote authenticated users to access arbitrary files in the web root via unspecified vectors.
CWE
CWE-22Affected Products
f5 enterprise managerf5 big-ip access policy managerf5 big-ip advanced firewall managerf5 big-ip analyticsf5 big-ip application acceleration managerf5 big-ip application security managerf5 big-ip edge gatewayf5 big-ip global traffic managerf5 big-ip link controllerf5 big-ip local traffic manager