CVE-2019-6687 describes a critical vulnerability in F5 BIG-IP ASM Cloud Security Services profiles, specifically versions 15.0.0 through 15.0.1.1. The flaw, categorized as CWE-295, stems from an inadequate X.509 certificate authentication mechanism for remote endpoints. This vulnerability carries a high CVSS score of 7.4, indicating a network-based attack with high complexity, but allowing an unauthenticated attacker to achieve high confidentiality and integrity impacts without user interaction. While not listed in CISA's KEV catalog and lacking public exploit intelligence like Metasploit or ExploitDB modules, there is also no significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.0.0, < 15.1.0CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.