← Back to CVEs
CVE-2015-8611
N/ADescription
BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, and PEM 12.0.0 before HF1 on the 2000, 4000, 5000, 7000, and 10000 platforms do not properly sync passwords with the Always-On Management (AOM) subsystem, which might allow remote attackers to obtain login access to AOM via an (1) expired or (2) default password.
CVE Details
CVSS v3.1 ScoreN/A
Published1/12/2016
Last Modified4/12/2025
Sourcenvd
Honeypot Sightings0
Affected Products
f5:big-ip_access_policy_managerf5:big-ip_advanced_firewall_managerf5:big-ip_analyticsf5:big-ip_application_acceleration_managerf5:big-ip_application_security_managerf5:big-ip_domain_name_systemf5:big-ip_link_controllerf5:big-ip_local_traffic_managerf5:big-ip_policy_enforcement_manager
Weaknesses (CWE)
CWE-255
References
http://www.securitytracker.com/id/1034629(cve@mitre.org)
http://www.securitytracker.com/id/1034629(af854a3a-2127-422b-91ae-364da2661108)
https://support.f5.com/kb/en-us/solutions/public/k/05/sol05272632.html(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.