Executive brief
F5 BIG-IP DNS, a solution used for managing global network traffic, contains a security flaw where sensitive SSH passwords are exposed in plain text. These passwords appear in certain administrative command responses and are recorded in system audit logs. A highly privileged attacker who already has administrative access could exploit this to view sensitive credentials, potentially leading to further unauthorized access within the network infrastructure.
Technical details
A cleartext storage of sensitive information vulnerability (CWE-312) exists in F5 BIG-IP DNS when provisioned. The 'gtm_add' and 'bigip_add' iControl REST commands return the 'ssh-password' parameter in cleartext within the REST response and subsequently record it in the system audit log. An attacker requires high privileges and local access to the management interface or audit logs to exploit this. Successful exploitation allows the attacker to retrieve sensitive credentials. F5 has released updates for affected versions, including 17.5.1.4 and 17.1.3.1, to address this issue.
Affected products
- F5 BIG-IP DNS 17.5.0 - 17.5.1, 17.1.0 - 17.1.3, 16.1.0 - 16.1.6
Timeline
- 2026-05-13: advisory: Initial advisory published by F5 Networks