On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when running in Appliance Mode, an authenticated user assigned the 'Administrator' role may be able to bypass Appliance Mode restrictions utilizing undisclosed iControl REST endpoints. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
Link | Resource |
---|---|
https://support.f5.com/csp/article/K74151369 | Vendor Advisory |
https://support.f5.com/csp/article/K74151369 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:51
Type | Values Removed | Values Added |
---|---|---|
References | () https://support.f5.com/csp/article/K74151369 - Vendor Advisory |
24 May 2021, 18:02
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://support.f5.com/csp/article/K74151369 - Vendor Advisory | |
CWE | CWE-863 | |
CPE | cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : 6.5
v3 : 7.2 |
Information
Published : 2021-05-10 15:15
Updated : 2024-11-21 05:51
NVD link : CVE-2021-23015
Mitre link : CVE-2021-23015
CVE.ORG link : CVE-2021-23015
JSON object : View
Products Affected
f5
- big-ip_access_policy_manager
- big-ip_global_traffic_manager
- big-ip_domain_name_system
- big-ip_application_acceleration_manager
- big-ip_policy_enforcement_manager
- big-ip_analytics
- big-ip_application_security_manager
- big-ip_ssl_orchestrator
- big-ip_advanced_web_application_firewall
- big-ip_ddos_hybrid_defender
- big-ip_advanced_firewall_manager
- big-ip_local_traffic_manager
- big-ip_fraud_protection_service
- big-ip_link_controller
CWE
CWE-863
Incorrect Authorization