Input validation error in BIG-IQ Centralized Management - CVE-2021-22996
Published: March 11, 2021
BIG-IQ Centralized Management
F5 Networks
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send specially crafted message to the BIG-IQ Data Collection Device (DCD) cluster member that was set up for auto failover and cause the corosync process to abort, which leads to a denial of service.