CyberSec.Space Logo
Back to CVE Browser

CVE-2021-23031

CRITICAL
9.9
CVSS Severity Score
EPSS Score0.1510%
EPSS Percentile18.56th
PublishedSep 14, 2021
Last ModifiedNov 21, 2024

Vulnerability Description

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5.3, an authenticated user may perform a privilege escalation on the BIG-IP Advanced WAF and ASM Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Platforms (CPE)

πŸ“¦
F5

Big Ip Advanced Web Application Firewall

>= 11.6.1 and <= 11.6.5.2
πŸ“¦
F5

Big Ip Advanced Web Application Firewall

>= 12.1.0 and <= 12.1.5
πŸ“¦
F5

Big Ip Advanced Web Application Firewall

>= 13.1.0 and <= 13.1.3
πŸ“¦
F5

Big Ip Advanced Web Application Firewall

>= 14.1.0 and <= 14.1.4
πŸ“¦
F5

Big Ip Advanced Web Application Firewall

>= 15.1.0 and <= 15.1.2
πŸ“¦
F5

Big Ip Advanced Web Application Firewall

>= 16.0.0 and <= 16.0.1.1
πŸ“¦
F5

Big Ip Application Security Manager

>= 11.6.1 and <= 11.6.5.2
πŸ“¦
F5

Big Ip Application Security Manager

>= 12.1.0 and <= 12.1.5
πŸ“¦
F5

Big Ip Application Security Manager

>= 13.1.0 and <= 13.1.3
πŸ“¦
F5

Big Ip Application Security Manager

>= 14.1.0 and <= 14.1.4
πŸ“¦
F5

Big Ip Application Security Manager

>= 15.1.0 and <= 15.1.2
πŸ“¦
F5

Big Ip Application Security Manager

>= 16.0.0 and <= 16.0.1.1

References & Advisories

Related Vulnerabilities