Buffer Overflow in BIG-IP DNS and GTM by F5 Networks
CVE-2021-22982

7.2HIGH

Key Information:

Vendor
F5
Vendor
CVE Published:
12 February 2021

Summary

A buffer overflow vulnerability exists in the BIG-IP DNS and GTM platforms on specific versions, where the big3d component fails to securely handle and parse certain payloads. This oversight could potentially allow an attacker to exploit this vulnerability to compromise the system's integrity. It's crucial for organizations using affected versions to assess their security measures and apply any necessary patches or mitigations, as systems in End of Software Development (EoSD) are not included in evaluation efforts.

Affected Version(s)

BIG-IP DNS and GTM 13.1.x before 13.1.0.4, and all versions of 12.1.x and 11.6.x

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.