PT-2021-2407 · F5 · Big-Ip

Published

2021-03-10

·

Updated

2021-04-05

·

CVE-2021-22989

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: BIG-IP versions 16.0.x through 16.0.1.1 BIG-IP versions 15.1.x through 15.1.2.1 BIG-IP versions 14.1.x through 14.1.4 BIG-IP versions 13.1.x through 13.1.3.6 BIG-IP versions 12.1.x through 12.1.5.3 BIG-IP versions 11.6.x through 11.6.5.3
Description: The issue is related to an authenticated remote command execution vulnerability in the TMUI, also referred to as the Configuration utility, when running in Appliance mode with Advanced WAF or BIG-IP ASM provisioned. This vulnerability is associated with inadequate access control in the Advanced WAF/ASM TMUI component of BIG-IP application security protections. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary commands, modify, or delete files.
Recommendations: For BIG-IP versions 16.0.x through 16.0.1.1, update to version 16.0.1.1 or later. For BIG-IP versions 15.1.x through 15.1.2.1, update to version 15.1.2.1 or later. For BIG-IP versions 14.1.x through 14.1.4, update to version 14.1.4 or later. For BIG-IP versions 13.1.x through 13.1.3.6, update to version 13.1.3.6 or later. For BIG-IP versions 12.1.x through 12.1.5.3, update to version 12.1.5.3 or later. For BIG-IP versions 11.6.x through 11.6.5.3, update to version 11.6.5.3 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01657
CVE-2021-22989

Affected Products

Big-Ip