On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 66
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
F5 Big-Ip_Access_Policy_Manager
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
|
11.6.1
|
<= 11.6.5
|
|
F5 Big-Ip_Access_Policy_Manager
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
|
12.1.0
|
<= 12.1.6
|
|
F5 Big-Ip_Access_Policy_Manager
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
|
13.1.0
|
13.1.5
|
|
F5 Big-Ip_Access_Policy_Manager
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
|
14.1.0
|
14.1.4.6
|
|
F5 Big-Ip_Access_Policy_Manager
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.5.1
|
|
F5 Big-Ip_Access_Policy_Manager
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.2.2
|
|
F5 Big-Ip_Advanced_Firewall_Manager
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
|
11.6.1
|
<= 11.6.5
|
|
F5 Big-Ip_Advanced_Firewall_Manager
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
|
12.1.0
|
<= 12.1.6
|
|
F5 Big-Ip_Advanced_Firewall_Manager
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
|
13.1.0
|
13.1.5
|
|
F5 Big-Ip_Advanced_Firewall_Manager
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
|
14.1.0
|
14.1.4.6
|
|
F5 Big-Ip_Advanced_Firewall_Manager
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.5.1
|
|
F5 Big-Ip_Advanced_Firewall_Manager
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.2.2
|
|
F5 Big-Ip_Analytics
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
|
11.6.1
|
<= 11.6.5
|
|
F5 Big-Ip_Analytics
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
|
12.1.0
|
<= 12.1.6
|
|
F5 Big-Ip_Analytics
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
|
13.1.0
|
13.1.5
|
|
F5 Big-Ip_Analytics
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
|
14.1.0
|
14.1.4.6
|
|
F5 Big-Ip_Analytics
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.5.1
|
|
F5 Big-Ip_Analytics
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.2.2
|
|
F5 Big-Ip_Application_Acceleration_Manager
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
|
11.6.1
|
<= 11.6.5
|
|
F5 Big-Ip_Application_Acceleration_Manager
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
|
12.1.0
|
<= 12.1.6
|
|
F5 Big-Ip_Application_Acceleration_Manager
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
|
13.1.0
|
13.1.5
|
|
F5 Big-Ip_Application_Acceleration_Manager
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
|
14.1.0
|
14.1.4.6
|
|
F5 Big-Ip_Application_Acceleration_Manager
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.5.1
|
|
F5 Big-Ip_Application_Acceleration_Manager
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.2.2
|
|
F5 Big-Ip_Application_Security_Manager
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
|
11.6.1
|
<= 11.6.5
|
|
F5 Big-Ip_Application_Security_Manager
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
|
12.1.0
|
<= 12.1.6
|
|
F5 Big-Ip_Application_Security_Manager
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
|
13.1.0
|
13.1.5
|
|
F5 Big-Ip_Application_Security_Manager
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
|
14.1.0
|
14.1.4.6
|
|
F5 Big-Ip_Application_Security_Manager
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.5.1
|
|
F5 Big-Ip_Application_Security_Manager
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.2.2
|
|
F5 Big-Ip_Domain_Name_System
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
|
11.6.1
|
<= 11.6.5
|
|
F5 Big-Ip_Domain_Name_System
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
|
12.1.0
|
<= 12.1.6
|
|
F5 Big-Ip_Domain_Name_System
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
|
13.1.0
|
13.1.5
|
|
F5 Big-Ip_Domain_Name_System
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
|
14.1.0
|
14.1.4.6
|
|
F5 Big-Ip_Domain_Name_System
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.5.1
|
|
F5 Big-Ip_Domain_Name_System
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.2.2
|
|
F5 Big-Ip_Fraud_Protection_Service
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
|
11.6.1
|
<= 11.6.5
|
|
F5 Big-Ip_Fraud_Protection_Service
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
|
12.1.0
|
<= 12.1.6
|
|
F5 Big-Ip_Fraud_Protection_Service
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
|
13.1.0
|
13.1.5
|
|
F5 Big-Ip_Fraud_Protection_Service
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
|
14.1.0
|
14.1.4.6
|
|
F5 Big-Ip_Fraud_Protection_Service
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.5.1
|
|
F5 Big-Ip_Fraud_Protection_Service
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.2.2
|
|
F5 Big-Ip_Global_Traffic_Manager
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
|
11.6.1
|
<= 11.6.5
|
|
F5 Big-Ip_Global_Traffic_Manager
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
|
12.1.0
|
<= 12.1.6
|
|
F5 Big-Ip_Global_Traffic_Manager
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
|
13.1.0
|
13.1.5
|
|
F5 Big-Ip_Global_Traffic_Manager
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
|
14.1.0
|
14.1.4.6
|
|
F5 Big-Ip_Global_Traffic_Manager
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.5.1
|
|
F5 Big-Ip_Global_Traffic_Manager
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.2.2
|
|
F5 Big-Ip_Link_Controller
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
|
11.6.1
|
<= 11.6.5
|
|
F5 Big-Ip_Link_Controller
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
|
12.1.0
|
<= 12.1.6
|
|
F5 Big-Ip_Link_Controller
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
|
13.1.0
|
13.1.5
|
|
F5 Big-Ip_Link_Controller
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
|
14.1.0
|
14.1.4.6
|
|
F5 Big-Ip_Link_Controller
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.5.1
|
|
F5 Big-Ip_Link_Controller
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.2.2
|
|
F5 Big-Ip_Local_Traffic_Manager
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
|
11.6.1
|
<= 11.6.5
|
|
F5 Big-Ip_Local_Traffic_Manager
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
|
12.1.0
|
<= 12.1.6
|
|
F5 Big-Ip_Local_Traffic_Manager
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
|
13.1.0
|
13.1.5
|
|
F5 Big-Ip_Local_Traffic_Manager
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
|
14.1.0
|
14.1.4.6
|
|
F5 Big-Ip_Local_Traffic_Manager
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.5.1
|
|
F5 Big-Ip_Local_Traffic_Manager
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.2.2
|
|
F5 Big-Ip_Policy_Enforcement_Manager
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
|
11.6.1
|
<= 11.6.5
|
|
F5 Big-Ip_Policy_Enforcement_Manager
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
|
12.1.0
|
<= 12.1.6
|
|
F5 Big-Ip_Policy_Enforcement_Manager
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
|
13.1.0
|
13.1.5
|
|
F5 Big-Ip_Policy_Enforcement_Manager
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
|
14.1.0
|
14.1.4.6
|
|
F5 Big-Ip_Policy_Enforcement_Manager
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
|
15.1.0
|
15.1.5.1
|
|
F5 Big-Ip_Policy_Enforcement_Manager
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
|
16.1.0
|
16.1.2.2
|