SB2021042918 - Security restrictions bypass in BIG-IP iControl REST API 



SB2021042918 - Security restrictions bypass in BIG-IP iControl REST API

Published: April 29, 2021

Security Bulletin ID SB2021042918
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper access control (CVE-ID: CVE-2021-23015)

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. When running in Appliance Mode, an authenticated user assigned the 'Administrator' role may be able to bypass Appliance Mode restrictions utilizing undisclosed iControl REST endpoints. A remote privileged user can bypass implemented security restrictions and gain unauthorized access to the application.


Remediation

Install update from vendor's website.