Cross-Site Request Forgery Vulnerability in F5 BIG-IP Products
CVE-2021-23050
Key Information:
- Vendor
F5
- Vendor
- CVE Published:
- 14 September 2021
What is CVE-2021-23050?
A vulnerability exists in F5 BIG-IP Advanced WAF and ASM versions prior to 16.0.1.2 and 15.1.3, along with all versions of NGINX App Protect. When a CSRF-enabled policy is configured on a virtual server, an unhandled HTML response may cause the bd process to unexpectedly terminate, resulting in potential disruption of service. It is crucial for users to upgrade to the latest versions to mitigate this risk and ensure optimal security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
BIG-IP Advanced WAF and BIG-IP ASM; NGINX App Protect BIG-IP Advanced WAF and BIG-IP ASM 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3
BIG-IP Advanced WAF and BIG-IP ASM; NGINX App Protect NGINX App Protect all versions before 3.5.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved