CVE-2012-1493 EXPLOIT
7.8
HIGH · CVSS 2.0 · EPSS 63.1% (pctl 99)
Patch early
A public exploit exists.
Description
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.
Scoring
| CVSS | 7.8 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
| EPSS | 63.08% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-255 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-07-09 |
| Last modified | 2026-06-16 |
Affected (25)
| Vendor | Product |
|---|---|
| f5 | big-ip 1000 |
| f5 | big-ip 11000 |
| f5 | big-ip 11050 |
| f5 | big-ip 1500 |
| f5 | big-ip 1600 |
| f5 | big-ip 2400 |
| f5 | big-ip 3400 |
| f5 | big-ip 3410 |
| f5 | big-ip 3600 |
| f5 | big-ip 3900 |
| f5 | big-ip 4100 |
| f5 | big-ip 5100 |
| f5 | big-ip 5110 |
| f5 | big-ip 6400 |
| f5 | big-ip 6800 |
| f5 | big-ip 6900 |
| f5 | big-ip 8400 |
| f5 | big-ip 8800 |
| f5 | big-ip 8900 |
| f5 | big-ip 8950 |
| f5 | big-ip application security manager |
| f5 | big-ip global traffic manager |
| f5 | big-ip local traffic manager |
| f5 | enterprise manager |
| f5 | tmos |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | F5 BIG-IP - SSH Private Key Exposure (Metasploit) | 2012-06-13 |
| exploit-db | F5 BIG-IP - Authentication Bypass | 2012-06-12 |
| exploit-db | F5 BIG-IP - Authentication Bypass (PoC) | 2012-06-11 |
References
- http://support.f5.com/kb/en-us/solutions/public/13000/600/sol13600.html
- http://www.theregister.co.uk/2012/06/13/f5_kit_metasploit_exploit/
- https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/ssh/f5_bigip_known_privkey.rb
- https://www.trustmatta.com/advisories/MATTA-2012-002.txt
- http://support.f5.com/kb/en-us/solutions/public/13000/600/sol13600.html
- http://www.theregister.co.uk/2012/06/13/f5_kit_metasploit_exploit/
- https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/ssh/f5_bigip_known_privkey.rb
- https://www.trustmatta.com/advisories/MATTA-2012-002.txt
→ the Explorer · watch your stack · NVD