Missing authentication for critical function in BIG-IQ Centralized Management - CVE-2021-22995
Published: March 11, 2021
BIG-IQ Centralized Management
F5 Networks
Description
The vulnerability allows a remote attacker to gain unauthorized access to the system.
The vulnerability exists due to missing authentication while accessing the Corosync daemon in
BIG-IQ high availability (HA) when using a Quorum device for automatic failover. A remote non-authenticated attacker can alter data or perform a denial of service (DoS) attack.