QID 375548
Date Published: 2021-05-24
QID 375548: F5 BIG-IP Appliance Mode Authenticated iControl REST Vulnerability(K74151369)
F5's BIG-IP is a family of products covering software and hardware designed around application availability, access control, and security solutions.
CVE-2021-23015: When running in Appliance Mode, an authenticated user assigned the 'Administrator' role may be able to bypass Appliance Mode restrictions utilizing undisclosed iControl REST endpoints.
Vulnerable Component: BIG-IP all modules
Affected Versions:
16.0.0 - 16.0.1
15.1.0 - 15.1.2
14.1.0 - 14.1.4
13.1.0.8 - 13.1.3
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
In Appliance Mode, an authenticated user with valid user credentials assigned the Administrator role may be able to bypass appliance mode restrictions and run arbitrary commands.
- K74151369 -
support.f5.com/csp/article/K74151369
CVEs related to QID 375548
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K74151369 |
|