Lucene search

K
f5F5F5:K66851119
HistoryMar 10, 2021 - 12:00 a.m.

K66851119 : F5 TMUI XSS vulnerability CVE-2021-22994

2021-03-1000:00:00
my.f5.com
12

5.9 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

57.1%

Security Advisory Description

Undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP system if the victim user is granted the admin role. This vulnerability is due to an incomplete fix for CVE-2020-5948. (CVE-2021-22994)

Impact

An attacker may exploit this vulnerability using a crafted URL to a reflected cross-site scripting (XSS) vulnerability in an undisclosed page of the Configuration utility, leading to a complete compromise of the BIG-IP system if the victim user is granted the admin role.

5.9 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

57.1%