F5 security briefs
4 published alerts for F5 products and services.
F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
F5 BIG-IP Configuration Utility is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-46747). F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748. CISA remediation due date: 2023-11-21. If you need help checking exposure, call (864) 335-9223.
F5 BIG-IP Missing Authentication Vulnerability
F5 BIG-IP is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-1388). F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services. CISA remediation due date: 2022-05-31. If you need help checking exposure, call (864) 335-9223.
F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability
F5 BIG-IP and BIG-IQ Centralized Management is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-22986). F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.
F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability
F5 BIG-IP is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-5902). F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.