Vulnerability record · CVE-2012-1493 · published 9 July 2012
CVE-2012-1493: F5 BIG-IP and Enterprise Manager shared SSH private key allows unauthorized logins
F5 · Big Ip Application Security Manager
F5 BIG-IP appliances and Enterprise Manager shipped with a single SSH private key reused across different customers' installations, and access to that key was not properly restricted. Because the key is shared and reachable, anyone who obtains it can authenticate to affected devices over SSH. This undermines the assumption that SSH access is per-device and per-customer.
Description
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.
AV:N/AC:L/Au:N/C:C/I:N/A:N
Automated analysis
high priorityA publicly available Metasploit module and very high EPSS score make exploitation likely, and successful SSH login grants full management access to the device.
What it is
F5 BIG-IP appliances and Enterprise Manager shipped with a single SSH private key reused across different customers' installations, and access to that key was not properly restricted. Because the key is shared and reachable, anyone who obtains it can authenticate to affected devices over SSH. This undermines the assumption that SSH access is per-device and per-customer.
Impact
An attacker with the shared key gains remote SSH login to affected appliances, exposing configuration and management access. The CVSS vector rates confidentiality impact as complete, with no integrity or availability impact stated.
Attack surface
Reachable over the network via SSH using the PubkeyAuthentication option; the CVSS vector AV:N/AC:L/Au:N indicates no authentication or user interaction is required to attempt the login. The description does not state whether the key is exposed through a separate channel or only via the appliance itself.
Exploitation
Not listed in CISA KEV, but EPSS is 0.63078 (99.166th percentile), and references include a Metasploit module tagged Exploit and Patch, indicating public exploit tooling exists. No ransomware usage is documented.
What to do
- Apply the F5 fixes for the affected branches: 9.4.8-HF5, 10.2.4, 11.0.0-HF2, 11.1.0-HF3, and Enterprise Manager 2.1.0-HF2, 2.2.0-HF1, 2.3.0-HF3.
- Replace the shared SSH host key material on affected devices and regenerate keys unique per installation.
- Restrict SSH management access to trusted networks and disable PubkeyAuthentication where it is not required.
- Rotate any credentials or trust relationships that relied on the shared key, and review SSH authorized_keys on affected systems.
Detection
- Audit SSH authorized_keys and host key fingerprints on BIG-IP and Enterprise Manager devices for the known shared key.
- Monitor SSH authentication logs for successful logins using the affected key from unexpected source addresses.
- Alert on SSH logins to management interfaces from outside approved administrative networks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
25 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1493 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1493), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.