Если на виртуальном сервере настроена политика доступа BIG-IP APM, определенный вредоносный трафик может привести к удаленному выполнению кода (RCE). Примечание. Версии программного обеспечения, для которых завершена техническая поддержка (EoTS), не оцениваются.
Показать оригинальное описание (EN)
When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Характеристики атаки
Последствия
Строка CVSS v4.0
Тип уязвимости (CWE)
Уязвимые продукты 83
| Конфигурация | От (включительно) | До (исключительно) |
|---|---|---|
|
F5 Big-Ip_Access_Policy_Manager
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Advanced_Firewall_Manager
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Advanced_Web_Application_Firewall
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Analytics
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Application_Acceleration_Manager
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Application_Security_Manager
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Application_Visibility_And_Reporting
cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Automation_Toolchain
cpe:2.3:a:f5:big-ip_automation_toolchain:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Carrier-Grade_Nat
cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Container_Ingress_Services
cpe:2.3:a:f5:big-ip_container_ingress_services:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Ddos_Hybrid_Defender
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Domain_Name_System
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Edge_Gateway
cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Fraud_Protection_Service
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Global_Traffic_Manager
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Link_Controller
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Local_Traffic_Manager
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Policy_Enforcement_Manager
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Ssl_Orchestrator
cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Webaccelerator
cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Websafe
cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.10.8
|
|
F5 Big-Ip_Access_Policy_Manager
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Advanced_Firewall_Manager
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Advanced_Web_Application_Firewall
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Analytics
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Application_Acceleration_Manager
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Application_Security_Manager
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Application_Visibility_And_Reporting
cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Automation_Toolchain
cpe:2.3:a:f5:big-ip_automation_toolchain:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Carrier-Grade_Nat
cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Container_Ingress_Services
cpe:2.3:a:f5:big-ip_container_ingress_services:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Ddos_Hybrid_Defender
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Domain_Name_System
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Edge_Gateway
cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Fraud_Protection_Service
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Global_Traffic_Manager
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Link_Controller
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Local_Traffic_Manager
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Policy_Enforcement_Manager
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Ssl_Orchestrator
cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Webaccelerator
cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Websafe
cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.6.1
|
|
F5 Big-Ip_Access_Policy_Manager
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Access_Policy_Manager
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|
|
F5 Big-Ip_Advanced_Firewall_Manager
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Advanced_Firewall_Manager
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|
|
F5 Big-Ip_Advanced_Web_Application_Firewall
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Advanced_Web_Application_Firewall
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|
|
F5 Big-Ip_Analytics
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Analytics
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|
|
F5 Big-Ip_Application_Acceleration_Manager
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Application_Acceleration_Manager
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|
|
F5 Big-Ip_Application_Security_Manager
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Application_Security_Manager
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|
|
F5 Big-Ip_Application_Visibility_And_Reporting
cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Application_Visibility_And_Reporting
cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|
|
F5 Big-Ip_Automation_Toolchain
cpe:2.3:a:f5:big-ip_automation_toolchain:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Automation_Toolchain
cpe:2.3:a:f5:big-ip_automation_toolchain:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|
|
F5 Big-Ip_Carrier-Grade_Nat
cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Carrier-Grade_Nat
cpe:2.3:a:f5:big-ip_carrier-grade_nat:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|
|
F5 Big-Ip_Container_Ingress_Services
cpe:2.3:a:f5:big-ip_container_ingress_services:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Container_Ingress_Services
cpe:2.3:a:f5:big-ip_container_ingress_services:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|
|
F5 Big-Ip_Ddos_Hybrid_Defender
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Ddos_Hybrid_Defender
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|
|
F5 Big-Ip_Domain_Name_System
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Domain_Name_System
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|
|
F5 Big-Ip_Edge_Gateway
cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Edge_Gateway
cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|
|
F5 Big-Ip_Fraud_Protection_Service
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Fraud_Protection_Service
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|
|
F5 Big-Ip_Global_Traffic_Manager
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Link_Controller
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Link_Controller
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|
|
F5 Big-Ip_Local_Traffic_Manager
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Local_Traffic_Manager
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|
|
F5 Big-Ip_Policy_Enforcement_Manager
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Policy_Enforcement_Manager
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|
|
F5 Big-Ip_Ssl_Orchestrator
cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Ssl_Orchestrator
cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|
|
F5 Big-Ip_Webaccelerator
cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Webaccelerator
cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|
|
F5 Big-Ip_Websafe
cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*
|
17.1.0
|
17.1.3
|
|
F5 Big-Ip_Websafe
cpe:2.3:a:f5:big-ip_websafe:*:*:*:*:*:*:*:*
|
17.5.0
|
<= 17.5.1
|