Description
F5 FirePass 5.4 through 5.5.1 does not properly enforce host access restrictions when a client uses a single integer (dword) representation of an IP address ("dotless IP address"), which allows remote authenticated users to connect to the FirePass administrator console and certain other network resources.
References (6)
Core 6
Core References
Various Sources x_refsource_misc
http://www.mnin.org/advisories/2007_firepass.pdf
Various Sources x_refsource_confirm
https://tech.f5.com/home/solutions/sol6922.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23640
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/32734
Mailing List mailing-list
x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/21957
Scores
EPSS
0.0084
EPSS Percentile
74.8%
Details
Status
published
Products (14)
f5/firepass
5.4
f5/firepass
5.4.1
f5/firepass
5.4.2
f5/firepass
5.4.3
f5/firepass
5.4.4
f5/firepass
5.4.5
f5/firepass
5.4.6
f5/firepass
5.4.7
f5/firepass
5.4.8
f5/firepass
5.4.9
... and 4 more
Published
Jan 12, 2007
Tracked Since
Feb 18, 2026