#VU51399 Resource exhaustion in BIG-IP ASM - CVE-2021-23001
Published: March 11, 2021
BIG-IP ASM
F5 Networks
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the upload functionality in BIG-IP ASM allows an authenticated user to
upload files to the BIG-IP system using a call to an undisclosed
iControl REST endpoint. A remote authenticated user can upload large files to the system, consume all available disk space and perform a denial of service (DoS) attack.