PT-2021-15324 · F5 · Big-Iq

Published

2021-03-31

·

Updated

2022-07-12

·

CVE-2021-22997

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions BIG-IQ versions 6.x through 7.x
Description The BIG-IQ HA ElasticSearch service does not implement authentication for clustering transport services, and all data used by ElasticSearch for transport is unencrypted.
Recommendations For versions 6.x and 7.x, update to version 8.0.0 to resolve the issue.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22997

Affected Products

Big-Iq