Lucene search

K
f5F5F5:K52420610
HistoryAug 24, 2021 - 12:00 a.m.

K52420610 : Advanced WAF and BIG-IP ASM TMUI vulnerability CVE-2021-23029

2021-08-2400:00:00
my.f5.com
10

8.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.9%

Security Advisory Description

Insufficient permission checks may allow authenticated users with guest privileges to perform Server-Side Request Forgery (SSRF) attacks through F5 Advanced Web Application Firewall (WAF) and the BIG-IP ASM Configuration utility. (CVE-2021-23029)

Impact

An attacker with network access to the management interface and authenticated with guest privileges may be able to perform an SSRF attack.

8.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.9%