ZeroHour

CVE-2017-6130

CVSS 3.0
7.4 high
EPSS
1%p65
Published
()
Modified
Description

F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attack when deployed using the Dynamic Domain Bypass (DDB) feature feature plus SNAT Auto Map option for egress traffic.

Vendors
f5
Products
ssl intercept iapp, ssl orchestrator
Weakness
CWE-918
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.