CVE-2021-23008: Critical severity F5 BIG-IP Access Policy Manager vulnerability
On version 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and all versions of 16.0.x and 11.6.x., BIG-IP APM AD (Active Directory) authentication can be bypassed via a spoofed AS-REP (Kerberos Authentication Service Response) response sent over a hijacked KDC (Kerberos Key Distribution Center) connection or from an AD server compromised by an attacker. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-23008?
CVE-2021-23008 is considered a critical vulnerability due to the potential for authentication bypass.
How do I fix CVE-2021-23008?
To fix CVE-2021-23008, upgrade to the latest version of BIG-IP APM, specifically versions 15.1.3, 14.1.4, 13.1.4, 12.1.6, or newer.
Which versions of BIG-IP APM are affected by CVE-2021-23008?
CVE-2021-23008 affects BIG-IP APM versions prior to 15.1.3, 14.1.4, 13.1.4, 12.1.6, and includes all versions of 16.0.x and 11.6.x.
What is the exploitation method for CVE-2021-23008?
CVE-2021-23008 can be exploited by sending a spoofed AS-REP response over a hijacked KDC to bypass authentication.
What impact does CVE-2021-23008 have on systems?
The impact of CVE-2021-23008 is significant as it allows unauthorized access to systems protected by BIG-IP APM.