CVE-2021-23047: Medium severity F5 BIG-IP Access Policy Manager vulnerability
On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, and all versions of 13.1.x, 12.1.x and 11.6.x, when BIG-IP APM performs Online Certificate Status Protocol (OCSP) verification of a certificate that contains Authority Information Access (AIA), undisclosed requests may cause an increase in memory use. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-23047?
CVE-2021-23047 has a high severity rating due to the potential for unauthorized requests during OCSP verification.
How do I fix CVE-2021-23047?
To fix CVE-2021-23047, upgrade your F5 Big-IP Access Policy Manager to the latest patched version available.
Which versions are affected by CVE-2021-23047?
CVE-2021-23047 affects multiple versions including 16.x before 16.1.0, and includes 15.1.x, 14.1.x, and earlier versions of F5 Big-IP APM.
What is Online Certificate Status Protocol (OCSP)?
Online Certificate Status Protocol (OCSP) is a protocol used to obtain the revocation status of an X.509 digital certificate.
Is CVE-2021-23047 a network vulnerability?
Yes, CVE-2021-23047 is considered a network vulnerability as it can be exploited through OCSP verification errors.