CVE Feed

    Dashboard / CVE / CVE-2012-1493

    CVE-2012-1493

    F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.

    Published:Jul 9, 2012
    Last Modified:Apr 11, 2025
    EPS:Jul 9, 2012
    EPSS Score:0.84375
    CVSS Score:7.8

    Affected Products

    Vendor
    F5
    Product
    Big-ip 1000
    Vendor
    F5
    Product
    Big-ip 11000
    Vendor
    F5
    Product
    Big-ip 11050
    Vendor
    F5
    Product
    Big-ip 1500
    Vendor
    F5
    Product
    Big-ip 1600
    Vendor
    F5
    Product
    Big-ip 2400
    Vendor
    F5
    Product
    Big-ip 3400
    Vendor
    F5
    Product
    Big-ip 3410
    Vendor
    F5
    Product
    Big-ip 3600
    Vendor
    F5
    Product
    Big-ip 3900
    Vendor
    F5
    Product
    Big-ip 4100
    Vendor
    F5
    Product
    Big-ip 5100
    Vendor
    F5
    Product
    Big-ip 5110
    Vendor
    F5
    Product
    Big-ip 6400
    Vendor
    F5
    Product
    Big-ip 6800
    Vendor
    F5
    Product
    Big-ip 6900
    Vendor
    F5
    Product
    Big-ip 8400
    Vendor
    F5
    Product
    Big-ip 8800
    Vendor
    F5
    Product
    Big-ip 8900
    Vendor
    F5
    Product
    Big-ip 8950
    Vendor
    F5
    Product
    Big-ip Application Security Manager
    Vendor
    F5
    Product
    Big-ip Global Traffic Manager
    Vendor
    F5
    Product
    Big-ip Local Traffic Manager
    Vendor
    F5
    Product
    Enterprise Manager
    Vendor
    F5
    Product
    Tmos

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High