← Vulnerability feed

Vulnerability record · CVE-2012-1493 · published 9 July 2012

CVE-2012-1493: F5 BIG-IP and Enterprise Manager shared SSH private key allows unauthorized logins

F5 · Big Ip Application Security Manager

F5 BIG-IP appliances and Enterprise Manager shipped with a single SSH private key reused across different customers' installations, and access to that key was not properly restricted. Because the key is shared and reachable, anyone who obtains it can authenticate to affected devices over SSH. This undermines the assumption that SSH access is per-device and per-customer.

7.8 CVSS 2.0 High EPSS 63% · top 0.8% CWE-255 · CWE-255
7.8CVSS 2.0 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
25Affected product versions listed by NVD
8References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.

AV:N/AC:L/Au:N/C:C/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityA publicly available Metasploit module and very high EPSS score make exploitation likely, and successful SSH login grants full management access to the device.

What it is

F5 BIG-IP appliances and Enterprise Manager shipped with a single SSH private key reused across different customers' installations, and access to that key was not properly restricted. Because the key is shared and reachable, anyone who obtains it can authenticate to affected devices over SSH. This undermines the assumption that SSH access is per-device and per-customer.

Impact

An attacker with the shared key gains remote SSH login to affected appliances, exposing configuration and management access. The CVSS vector rates confidentiality impact as complete, with no integrity or availability impact stated.

Attack surface

Reachable over the network via SSH using the PubkeyAuthentication option; the CVSS vector AV:N/AC:L/Au:N indicates no authentication or user interaction is required to attempt the login. The description does not state whether the key is exposed through a separate channel or only via the appliance itself.

Exploitation

Not listed in CISA KEV, but EPSS is 0.63078 (99.166th percentile), and references include a Metasploit module tagged Exploit and Patch, indicating public exploit tooling exists. No ransomware usage is documented.

What to do

  • Apply the F5 fixes for the affected branches: 9.4.8-HF5, 10.2.4, 11.0.0-HF2, 11.1.0-HF3, and Enterprise Manager 2.1.0-HF2, 2.2.0-HF1, 2.3.0-HF3.
  • Replace the shared SSH host key material on affected devices and regenerate keys unique per installation.
  • Restrict SSH management access to trusted networks and disable PubkeyAuthentication where it is not required.
  • Rotate any credentials or trust relationships that relied on the shared key, and review SSH authorized_keys on affected systems.

Detection

  • Audit SSH authorized_keys and host key fingerprints on BIG-IP and Enterprise Manager devices for the known shared key.
  • Monitor SSH authentication logs for successful logins using the affected key from unexpected source addresses.
  • Alert on SSH logins to management interfaces from outside approved administrative networks.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

25 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1493 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2012-1493), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.