Remote Command Execution Vulnerability in F5 BIG-IQ Configuration Utility
CVE-2021-23024
7.2HIGH
Summary
The BIG-IQ Configuration Utility from F5 Networks is susceptible to an authenticated remote command execution vulnerability that affects all versions prior to 8.0.0.1 in the 8.0.x branch, along with the 6.x and 7.x versions. This vulnerability occurs in undisclosed pages, potentially allowing attackers with valid credentials to execute arbitrary commands on the affected system, thereby compromising its security. Users are advised to upgrade to the latest version to mitigate any risk associated with this vulnerability.
Affected Version(s)
BIG-IQ 8.0.x before 8.0.0.1, and all 6.x and 7.x versions
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved