PT-2021-3230 · F5 · F5 Big-Iq Centralized Management

Published

2021-06-02

·

Updated

2021-09-20

·

CVE-2021-23024

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions F5 BIG-IQ Centralized Management versions 6.x and 7.x and versions 8.0.x before 8.0.0.1
Description The issue is related to insufficient validation of arguments passed to a command, allowing a remote attacker to execute arbitrary commands on the target system by inputting specially crafted management commands. This can lead to authenticated remote command execution.
Recommendations For versions 6.x and 7.x, consider disabling the vulnerable command execution functionality until a patch is available. For versions 8.0.x before 8.0.0.1, update to version 8.0.0.1 or later to resolve the issue.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02936
CVE-2021-23024

Affected Products

F5 Big-Iq Centralized Management