QID 730038
Date Published: 2021-04-07
QID 730038: F5 BIG-IP Configuration Utility Default Credential Vulnerability
F5 ships BIG-IP systems with default values for several system settings.
QID Detection Logic:
This QID sends GET request to mgmt/tm/sys/license with credentials admin:admin.
A remote attacker could exploit this to perform sensitive actions and take control over the device.
Solution
Customers are advised not to use default credentials for F5 BIG-IP.
Vendor References
- K13148 -
support.f5.com/csp/article/K13148
CVEs related to QID 730038
Software Advisories
| Advisory ID | Software | Component | Link |
|---|