← Vulnerability feed

Vulnerability record · CVE-2012-1777 · published 5 April 2012

CVE-2012-1777: F5 firepass sql injection vulnerability

F5 · Firepass

SQL injection vulnerability in my.activation.php3 in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 allows remote attackers to execute arbitrary SQL commands via the state parameter.

7.5 CVSS 2.0 High EPSS 2.3% · top 17.3% CWE-89 · SQL injection
7.5CVSS 2.0 base score
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in my.activation.php3 in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 allows remote attackers to execute arbitrary SQL commands via the state parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1777 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2014-2927F5 arx improper authentication vulnerabilityThe rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and …EPSS 7.9%9.3CVE-2013-0150F5 big-ip access policy manager path traversal vulnerabilityDirectory traversal vulnerability in an unspecified signed Java applet in the client-side components in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.0.…EPSS 6.3%9.1CVE-2011-3188Linux kernel vulnerabilityThe (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Ident…EPSS 5.0%7.5CVE-2007-0187F5 firepass vulnerabilityF5 FirePass 5.4 through 5.5.2 and 6.0 allows remote attackers to access restricted URLs via (1) a trailing null byte, (2) multiple leading slashes, (…EPSS 3.7%7.2CVE-2012-2053F5 firepass permissions and access controls vulnerabilityThe sudoers file in the Linux system configuration in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 does not require a password for executing commands as…EPSS 0.48%6.5CVE-2007-0188F5 firepass vulnerabilityF5 FirePass 5.4 through 5.5.1 does not properly enforce host access restrictions when a client uses a single integer (dword) representation of an IP …EPSS 1.4%5.9CVE-2013-3587F5 big-ip access policy manager information exposure vulnerabilityThe HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted d…EPSS 6.0%5.0CVE-2007-0195F5 firepass vulnerabilitymy.activation.php3 in F5 FirePass 5.4 through 5.5.1 and 6.0 displays different error messages for failed login attempts with a valid username than fo…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2012-1777), CISA KEV, FIRST EPSS (scores of 2026-09-30). This page is refreshed as NVD updates the record.