F5-K98606833: Medium severity f5 big-ip and big-iq centralized management vulnerability
BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced Shell (bash) can execute arbitrary commands with a specially crafted command string. This vulnerability is due to an incomplete fix for CVE-2020-5873.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K98606833?
The severity of F5-K98606833 is critical due to the potential for arbitrary command execution.
How do I fix F5-K98606833?
To fix F5-K98606833, update your F5 BIG-IP or BIG-IQ management systems to the recommended patched versions listed in the advisory.
Who is affected by F5-K98606833?
F5-K98606833 affects Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility.
What versions are vulnerable to F5-K98606833?
F5-K98606833 affects F5 BIG-IP versions 15.1.0 to 15.1.8, 16.1.0 to 16.1.3, and 17.1.0, as well as F5 BIG-IQ versions 8.0.0 to 8.3.0.
What is the nature of the vulnerability in F5-K98606833?
The vulnerability in F5-K98606833 allows for arbitrary command execution due to an incomplete fix related to CVE-2020-5873.