CVE-2021-23024: Critical severity F5 BIG-IQ Centralized Management vulnerability
On version 8.0.x before 8.0.0.1, and all 6.x and 7.x versions, the BIG-IQ Configuration utility has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-23024?
CVE-2021-23024 is an authenticated remote command execution vulnerability in the BIG-IQ Configuration utility.
What versions are affected by CVE-2021-23024?
Versions 8.0.x before 8.0.0.1, and all 6.x and 7.x versions of the F5 BIG-IQ Centralized Management software are affected.
How severe is CVE-2021-23024?
CVE-2021-23024 has a severity rating of 7.2 (critical).
How can I fix CVE-2021-23024?
To fix CVE-2021-23024, upgrade to version 8.0.0.1 if you are on version 8.0.x, or upgrade to a version after 7.1.0 if you are on versions 6.x or 7.x.
Where can I find more information about CVE-2021-23024?
You can find more information about CVE-2021-23024 at the following references: [Packet Storm Security](http://packetstormsecurity.com/files/163264/F5-BIG-IQ-VE-8.0.0-2923215-Remote-Root.html) and [F5 Support](https://support.f5.com/csp/article/K06024431).