PT-2024-1930 · F5 · Big-Ip+3
Published
2024-02-14
·
Updated
2025-01-23
·
CVE-2024-21782
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BIG-IP versions prior to the fixed version
BIG-IQ versions prior to the fixed version
Description
The issue allows BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced shell (bash) to execute arbitrary commands with a specially crafted command string. This is due to an incomplete fix for a previous issue. The vulnerability is also related to an unlimited file upload of dangerous types in various BIG-IP modules, including Access Policy Manager, Advanced Firewall Manager, and others. Exploitation of the vulnerability may allow an attacker to execute arbitrary commands.
Recommendations
For BIG-IP versions prior to the fixed version, consider disabling the
scp utility until a patch is available.
For BIG-IQ versions prior to the fixed version, consider restricting access to the scp utility until a patch is available.
As a temporary workaround, consider limiting the upload of files to prevent exploitation of the unlimited file upload vulnerability in affected BIG-IP modules.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Access Policy Manager
Advanced Firewall Manager
Big-Ip
Big-Iq