Open Redirection Vulnerability in F5 BIG-IP Advanced WAF and ASM
CVE-2021-22984

6.1MEDIUM

Key Information:

Vendor
F5
Vendor
CVE Published:
12 February 2021

Summary

The vulnerability in F5 BIG-IP Advanced WAF and ASM allows for Open Redirection attacks when an unauthenticated client sends a crafted URI. This can impact clients and web servers when using a DoS profile with Proactive Bot Defense or Bot Defense profile settings. It specifically affects multiple versions of the software, opening the door for malicious users to redirect traffic in unsanctioned ways, potentially leading to further exploitation or data breaches.

Affected Version(s)

BIG-IP Advanced WAF & BIG-IP ASM 15.1.x before 15.1.0.2, 15.0.x before 15.0.1.4, 14.1.x before 14.1.2.5, 13.1.x before 13.1.3.4, 12.1.x before 12.1.5.2, and 11.6.x before 11.6.5.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.