First published: Tue Sep 14 2021(Updated: )
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Access Policy Manager | >=15.1.0<15.1.3 | |
F5 BIG-IP Access Policy Manager | >=16.0.0<16.0.1.2 | |
F5 BIG-IP Advanced Firewall Manager | >=15.1.0<15.1.3 | |
F5 BIG-IP Advanced Firewall Manager | >=16.0.0<16.0.1.2 | |
F5 Big-ip Advanced Web Application Firewall | >=15.1.0<15.1.3 | |
F5 Big-ip Advanced Web Application Firewall | >=16.0.0<16.0.1.2 | |
F5 BIG-IP Analytics | >=15.1.0<15.1.3 | |
F5 BIG-IP Analytics | >=16.0.0<16.0.1.2 | |
F5 Big-ip Application Acceleration Manager | >=15.1.0<15.1.3 | |
F5 Big-ip Application Acceleration Manager | >=16.0.0<16.0.1.2 | |
F5 BIG-IP Application Security Manager | >=15.1.0<15.1.3 | |
F5 BIG-IP Application Security Manager | >=16.0.0<16.0.1.2 | |
F5 Big-ip Domain Name System | >=15.1.0<15.1.3 | |
F5 Big-ip Domain Name System | >=16.0.0<16.0.1.2 | |
F5 Big-ip Fraud Protection Service | >=15.1.0<15.1.3 | |
F5 Big-ip Fraud Protection Service | >=16.0.0<16.0.1.2 | |
F5 Big-ip Global Traffic Manager | >=15.1.0<15.1.3 | |
F5 Big-ip Global Traffic Manager | >=16.0.0<16.0.1.2 | |
F5 Big-ip Link Controller | >=15.1.0<15.1.3 | |
F5 Big-ip Link Controller | >=16.0.0<16.0.1.2 | |
F5 Big-ip Local Traffic Manager | >=15.1.0<15.1.3 | |
F5 Big-ip Local Traffic Manager | >=16.0.0<16.0.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23049 is a vulnerability on BIG-IP version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3 that can cause an out-of-memory condition and denial-of-service.
CVE-2021-23049 affects F5 BIG-IP products, including Access Policy Manager, Advanced Firewall Manager, Advanced Web Application Firewall, Analytics, Application Acceleration Manager, Application Security Manager, Domain Name System, Fraud Protection Service, Global Traffic Manager, Link Controller, and Local Traffic Manager.
CVE-2021-23049 has a severity rating of 7.5, which is considered high.
To mitigate the vulnerability in CVE-2021-23049, upgrade to BIG-IP version 16.0.1.2 or 15.1.3, or apply the necessary patches provided by F5 Networks.
You can find more information about CVE-2021-23049 on the F5 Networks support website: https://support.f5.com/csp/article/K65397301