← back
CVE-2012-1493

CVE-2012-1493

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 63%
from disclosure to weapon0 days
Published on NVDJul 9
1st PoCJun 11
metasploitJun 11
exploitation probability
63%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.