First published: Wed May 03 2023(Updated: )
An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ system can upload arbitrary files using an undisclosed iControl REST endpoint.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IQ Centralized Management | >=8.0.0<=8.2.0 | 8.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of F5-K000132719 is critical due to the potential for unauthorized file uploads.
To fix F5-K000132719, upgrade to a patched version of BIG-IQ Centralized Management above 8.3.0.
F5-K000132719 affects users with Viewer or Auditor roles on BIG-IQ Centralized Management versions between 8.0.0 and 8.2.0.
The impact of F5-K000132719 includes the ability for authenticated attackers to upload arbitrary files, potentially leading to further exploitation.
Currently, there is no workaround for F5-K000132719 other than updating to a secure version.