First published: Thu Jun 10 2021(Updated: )
On version 8.0.x before 8.0.0.1, and all 6.x and 7.x versions, the BIG-IQ Configuration utility has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IQ Centralized Management | >=6.0.0<=6.1.0 | |
F5 BIG-IQ Centralized Management | >=7.0.0<=7.1.0 | |
F5 BIG-IQ Centralized Management | >=8.0.0<8.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23024 is an authenticated remote command execution vulnerability in the BIG-IQ Configuration utility.
Versions 8.0.x before 8.0.0.1, and all 6.x and 7.x versions of the F5 BIG-IQ Centralized Management software are affected.
CVE-2021-23024 has a severity rating of 7.2 (critical).
To fix CVE-2021-23024, upgrade to version 8.0.0.1 if you are on version 8.0.x, or upgrade to a version after 7.1.0 if you are on versions 6.x or 7.x.
You can find more information about CVE-2021-23024 at the following references: [Packet Storm Security](http://packetstormsecurity.com/files/163264/F5-BIG-IQ-VE-8.0.0-2923215-Remote-Root.html) and [F5 Support](https://support.f5.com/csp/article/K06024431).