PT-2021-15374 · Amazon+1 · Ena+1
Published
2021-09-14
·
Updated
2021-09-27
·
CVE-2021-23051
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP versions 15.1.0.4 through 15.1.3
Description
The issue occurs when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP on Amazon Web Services (AWS) systems. Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate due to an incomplete fix for a previously known issue.
Recommendations
For versions 15.1.0.4 through 15.1.3, consider disabling the DPDK/ENA driver as a temporary workaround until a patch is available. Restrict access to the TMM to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ena
F5 Big-Ip