Transport Layer Security Flaw in BIG-IQ by F5 Networks
CVE-2021-23005
9.1CRITICAL
Summary
The identified vulnerability affects F5 Networks' BIG-IQ versions 7.x and 6.x, where the system using Quorum devices for high availability (HA) fails to employ Transport Layer Security (TLS) during communication with the Corosync protocol. This oversight in encrypting data can expose sensitive information to potential interception and compromise the integrity of failover operations. Users are advised to upgrade to version 8.0.0 or apply mitigations to safeguard their deployments.
Affected Version(s)
BIG-IQ All 7.x and 6.x versions
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved