4.3
CVSSv2

CVE-2015-4637

Published: 16/07/2015 Updated: 21/07/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The REST API in F5 BIG-IQ Cloud, Device, and Security 4.4.0 and 4.5.0 before HF2 and ADC 4.5.0 before HF2, when configured for LDAP remote authentication and the LDAP server allows anonymous BIND operations, allows remote malicious users to obtain an authentication token for arbitrary users by guessing an LDAP user account name.

Vulnerable Product Search on Vulmon Subscribe to Product

f5 big-iq cloud 4.5.0

f5 big-iq device 4.4.0

f5 big-iq device 4.5.0

f5 big-iq security 4.4.0

f5 big-iq cloud 4.4.0

f5 big-iq security 4.5.0

f5 big-iq adc 4.5.0