SB2021031118 - Missing authentication in BIG-IQ HA ElasticSearch
Published: March 11, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing authentication for critical function (CVE-ID: CVE-2021-22997)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the BIG-IQ HA ElasticSearch service does not implement any form of
authentication for the clustering transport services, and all data used
by ElasticSearch for transport is unencrypted. A remote non-authenticated attacker can gain access to sensitive information or modify it.
Remediation
Install update from vendor's website.