LiveActive security incident?Get immediate response
CVE Record

CVE-2019-6642: In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0...

In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, authenticated users with the ability to upload files (via scp, for example) can escalate their privileges to allow root shell access from within the TMOS Shell (tmsh) interface. The tmsh interface allows users to execute a secondary program via tools like sftp or scp.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

This is an F5 privilege-escalation issue. A logged-in user who can upload files to vulnerable BIG-IP or related management products may be able to move from restricted TMOS Shell access to root shell access. The main business risk is a compromised or over-privileged operator account becoming full device compromise.

Executive priority

Treat as high priority where vulnerable F5 systems are administered by multiple users or exposed to less-trusted administrative networks. The issue requires authenticated access, but root-level compromise of F5 infrastructure can affect traffic control, availability, and security enforcement.

Technical view

Authenticated users with file-upload capability, such as through scp, can escalate privileges from within the TMOS Shell interface because tmsh can invoke secondary programs such as sftp or scp. The affected products and versions are the F5 BIG-IP, BIG-IQ, iWorkflow, and Enterprise Manager ranges listed in the CVE record.

Likely exposure

Exposure is limited to organizations running the listed F5 versions and allowing authenticated users to upload files or use tmsh pathways that invoke secondary tools. Internet exposure alone is not sufficient evidence; account permissions and management-plane access matter.

Exploitation context

The provided bundle does not show CISA KEV listing or other evidence of active exploitation. Exploitation requires an authenticated user with file-upload capability. The consequence is severe because successful abuse may provide root shell access on sensitive traffic or management infrastructure.

Researcher notes

The source bundle gives affected version ranges and the privilege-escalation condition, but does not include CVSS, CWE, fixed versions, workaround detail, or exploit-in-the-wild evidence. Avoid assuming unauthenticated exploitation or specific patch levels beyond the F5 advisory.

Mitigation direction

  • Check F5 advisory K40378764 for the vendor-supported fix or workaround.
  • Upgrade affected F5 products only to versions approved by F5 guidance.
  • Restrict tmsh, scp, and sftp access to trusted administrative users.
  • Remove file-upload privileges from accounts that do not require them.
  • Review administrative account hygiene and enforce least privilege.

Validation and detection

  • Inventory F5 BIG-IP, BIG-IQ, iWorkflow, and Enterprise Manager versions.
  • Compare deployed versions against the affected ranges in the CVE record.
  • Identify accounts with tmsh access and file-upload capability.
  • Review management access logs for unexpected file uploads or privilege changes.
  • Confirm remediation status against F5 advisory K40378764.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2019-6642 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
F5BIG-IP, BIG-IQ, iWorkflow, Enterprise ManagerBIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0, 5.1.0-5.4.0, iWorkflow 2.3.0, Enterprise Manager 3.1.1Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.