AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-6642

HIGH · CVSS 8.8 EPSS 1.82%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-07-01 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-6642
Severity
HIGH
CVSS
8.8
EPSS
1.82%
BIG-IP

Original NVD Description

In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, authenticated users with the ability to upload files (via scp, for example) can escalate their privileges to allow root shell access from within the TMOS Shell (tmsh) interface. The tmsh interface allows users to execute a secondary program via tools like sftp or scp.