F5 Releases Security Updates
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
F5 have released an overview of vulnerabilities for some of their networking products, including BIG-IP and BIG-IQ. Over 30 vulnerabilities and security exposures are included in the advisory, with 13 CVEs rating High impact.
The high impact vulnerabilities relate to authenticated remote command execution, cross-site forgery, cross-site scripting, unexpected process termination, server-side request forgery, and privilege escalation. A remote attacker could exploit these vulnerabilities to take control of an affected system.
CVE-2021-23031, affecting BIG-IP modules Advanced Web Application Firewall (WAF) and the Application Security Manager (ASM), might be elevated from a CVSS score of 8.8 to a critical 9.9 if it is used in Appliance Mode.
Remediation advice
Affected organisations are encouraged to review F5 security advisory K50974556 and apply any relevant updates or mitigations.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 26 August 2021 1:54 pm