Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected Platforms (CPE)
📦
F5
Big Ip Access Policy Manager
>= 13.1.0 and <= 13.1.5>= 14.1.0 and <= 14.1.5>= 15.1.0 and <= 15.1.10>= 16.1.0 and <= 16.1.4>= 17.1.0 and <= 17.1.1
📦
F5
Big Ip Advanced Firewall Manager
>= 13.1.0 and <= 13.1.5>= 14.1.0 and <= 14.1.5>= 15.1.0 and <= 15.1.10>= 16.1.0 and <= 16.1.4>= 17.1.0 and <= 17.1.1
📦
F5
Big Ip Advanced Web Application Firewall
>= 13.1.0 and <= 13.1.5>= 14.1.0 and <= 14.1.5>= 15.1.0 and <= 15.1.10>= 16.1.0 and <= 16.1.4>= 17.1.0 and <= 17.1.1
📦
F5
Big Ip Carrier Grade Nat
>= 13.1.0 and <= 13.1.5>= 14.1.0 and <= 14.1.5>= 15.1.0 and <= 15.1.10>= 16.1.0 and <= 16.1.4>= 17.1.0 and <= 17.1.1