CVE-2021-23012 Information

Description

On BIG-IP versions 16.0.x before 16.0.1.1 15.1.x before 15.1.3 14.1.x before 14.1.4 and 13.1.x before 13.1.4 lack of input validation for items used in the system support functionality may allow users granted either \Resource Administrator\ or \Administrator\ roles to execute arbitrary bash commands on BIG-IP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Reference

https://support.f5.com/csp/article/K04234247

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction Required

HIGH

Scope

NONE

Confidentiality Impact

CHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.2

Share on: