Lucene search

K
f5F5F5:K51213246
HistoryApr 28, 2021 - 12:00 a.m.

K51213246 : BIG-IP APM AD authentication vulnerability CVE-2021-23008

2021-04-2800:00:00
my.f5.com
17

7 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

74.6%

Security Advisory Description

BIG-IP APM AD (Active Directory) authentication can be bypassed using a spoofed AS-REP (Kerberos Authentication Service Response) response sent over a hijacked KDC (Kerberos Key Distribution Center) connection, or from an AD server compromised by an attacker.(CVE-2021-23008)

Impact

A remote attacker can hijack a KDC connection using a spoofed AS-REP response. For an APM access policy configured with AD authentication and SSO (single sign-on) agent, if a spoofed credential related to this vulnerability is used, depending how the back-end system validates the authentication token it receives, access will most likely fail. An APM access policy can also be configured for BIG-IP system authentication. A spoofed credential related to this vulnerability for an administrative user through the APM access policy results in local administrative access.

7 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

74.6%