Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pq6p-fc96-wc5w

Опубликовано: 26 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

EPSS

Процентиль: 100%
0.94436
Критический

9.8 Critical

CVSS3

Дефекты

CWE-288
CWE-306

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 9.8
fstec
больше 2 лет назад

Уязвимость утилиты настройки программных продуктов BIG-IP средства контроля доступа и удаленной аутентификации BIG-IP Access Policy Manager, а также программных средств BIG-IP Advanced Firewall Manager, BIG-IP Analytics, BIG-IP Application Acceleration Manager, BIG-IP Application Security Manager, BIG-IP Hybrid Defender, BIG-IP Domain Name System, BIG-IP Fraud Protection Service, BIG-IP Link Controller, BIG-IP Local Traffic Manager, BIG-IP Policy Enforcement Manager, BIG-IP Orchestrator, связанная с возможностью обхода процедуры аутентификации посредством использования альтернативного пути или канала, позволяющая нарушителю выполнить произвольные системные команды

EPSS

Процентиль: 100%
0.94436
Критический

9.8 Critical

CVSS3

Дефекты

CWE-288
CWE-306