Weak Permissions in F5 BIG-IP Edge Client Windows Installer Service
CVE-2021-23022

7.8HIGH

Key Information:

Vendor
F5
Vendor
CVE Published:
10 June 2021

Summary

The BIG-IP Edge Client for Windows has a vulnerability that arises from weak file and folder permissions in its installer service's temporary directory. This could allow unauthorized users to manipulate or access sensitive data. Users of versions 7.2.1.x prior to 7.2.1.3 and 7.1.x prior to 7.1.9.9 Update 1 are urged to evaluate their systems and apply the necessary updates to mitigate this vulnerability.

Affected Version(s)

Edge Client for Windows 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.