QID 376070
Date Published: 2021-11-18
QID 376070: F5 BIG-IP Application Security Manager (ASM), Access Policy Manager (APM), Local Traffic Manager (LTM) iAppsLX REST Vulnerability (K50343630)
When an authenticated administrative user installs RPMs using the iAppsLX REST installer, the BIG-IP system does not sufficiently validate user input, allowing the user read access to the filesystem.CVE-2020-27727
Vulnerable Component: BIG-IP APM,LTM,ASM
Affected Versions:
16.0.0
15.0.0 - 15.1.0
14.1.0 - 14.1.3
13.1.0 - 13.1.3
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
An attacker can exploit this vulnerability as an authenticated administrative user to get read-only access as root user to the filesystem on the BIG-IP system.
Solution
The vendor has released patch, for more information please visit: K50343630
Vendor References
- K50343630 -
support.f5.com/csp/article/K50343630
CVEs related to QID 376070
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K50343630 |
|