← Vulnerability feed

Vulnerability record · CVE-2012-2053 · published 5 April 2012

CVE-2012-2053: F5 firepass permissions and access controls vulnerability

F5 · Firepass

The sudoers file in the Linux system configuration in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 does not require a password for executing commands as root, which allows local users to gain privileges via the sudo program, as demonstrated by the user account that executes PHP scripts, a different vulnerability than CVE-2012-1777.

7.2 CVSS 2.0 High EPSS 0.48% · top 60.9% CWE-264 · Permissions and access controls
7.2CVSS 2.0 base score
0.48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The sudoers file in the Linux system configuration in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 does not require a password for executing commands as root, which allows local users to gain privileges via the sudo program, as demonstrated by the user account that executes PHP scripts, a different vulnerability than CVE-2012-1777.

AV:L/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-2053 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2014-2927F5 arx improper authentication vulnerabilityThe rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and …EPSS 7.9%9.3CVE-2013-0150F5 big-ip access policy manager path traversal vulnerabilityDirectory traversal vulnerability in an unspecified signed Java applet in the client-side components in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.0.…EPSS 6.3%9.1CVE-2011-3188Linux kernel vulnerabilityThe (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Ident…EPSS 5.0%7.5CVE-2012-1777F5 firepass sql injection vulnerabilitySQL injection vulnerability in my.activation.php3 in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 allows remote attackers to execute arbitrary SQL comma…EPSS 2.3%7.5CVE-2007-0187F5 firepass vulnerabilityF5 FirePass 5.4 through 5.5.2 and 6.0 allows remote attackers to access restricted URLs via (1) a trailing null byte, (2) multiple leading slashes, (…EPSS 3.7%6.5CVE-2007-0188F5 firepass vulnerabilityF5 FirePass 5.4 through 5.5.1 does not properly enforce host access restrictions when a client uses a single integer (dword) representation of an IP …EPSS 1.4%5.9CVE-2013-3587F5 big-ip access policy manager information exposure vulnerabilityThe HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted d…EPSS 6.0%5.0CVE-2007-0195F5 firepass vulnerabilitymy.activation.php3 in F5 FirePass 5.4 through 5.5.1 and 6.0 displays different error messages for failed login attempts with a valid username than fo…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2012-2053), CISA KEV, FIRST EPSS (scores of 2026-09-30). This page is refreshed as NVD updates the record.