CVE-2015-4040 describes a directory traversal vulnerability in the configuration utility of F5 BIG-IP (versions prior to 12.0.0) and Enterprise Manager (versions 3.0.0 through 3.1.1). This flaw allows remote authenticated users to access arbitrary files within the web root. With a CVSS score of 4.0, this vulnerability has a low severity, requiring authentication (Au:S) for exploitation and primarily impacting confidentiality (C:P) with no integrity or availability impact. While not listed on the KEV catalog and showing no active exploitation, a public exploit (EDB-38448) exists, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.0CPE matchmatch criteria | cpe:2.3:a:f5:enterprise_manager:3.0.0:*:*:*:*:*:*:* | ||
3.1.0CPE matchmatch criteria | cpe:2.3:a:f5:enterprise_manager:3.1.0:*:*:*:*:*:*:* | ||
3.1.1CPE matchmatch criteria | cpe:2.3:a:f5:enterprise_manager:3.1.1:*:*:*:*:*:*:* | ||
<= 11.6.0CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* | ||
<= 11.6.0CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.