peter bassill · operator
$ cve CVE-2012-1493 JSON

CVE-2012-1493 EXPLOIT

7.8
HIGH · CVSS 2.0 · EPSS 63.1% (pctl 99)

Patch early

A public exploit exists.

Description

F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.

Scoring

CVSS7.8 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
EPSS63.08% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-255
On CISA KEVno
Public exploityes
Published2012-07-09
Last modified2026-06-16

Affected (25)

VendorProduct
f5big-ip 1000
f5big-ip 11000
f5big-ip 11050
f5big-ip 1500
f5big-ip 1600
f5big-ip 2400
f5big-ip 3400
f5big-ip 3410
f5big-ip 3600
f5big-ip 3900
f5big-ip 4100
f5big-ip 5100
f5big-ip 5110
f5big-ip 6400
f5big-ip 6800
f5big-ip 6900
f5big-ip 8400
f5big-ip 8800
f5big-ip 8900
f5big-ip 8950
f5big-ip application security manager
f5big-ip global traffic manager
f5big-ip local traffic manager
f5enterprise manager
f5tmos

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD