Missing authentication for critical function in BIG-IQ Centralized Management - CVE-2021-22997
Published: March 11, 2021
BIG-IQ Centralized Management
F5 Networks
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the BIG-IQ HA ElasticSearch service does not implement any form of
authentication for the clustering transport services, and all data used
by ElasticSearch for transport is unencrypted. A remote non-authenticated attacker can gain access to sensitive information or modify it.