Input validation error in BIG-IP ASM - CVE-2021-23010
Published: April 29, 2021
BIG-IP ASM
F5 Networks
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when processing WebSocket requests with JSON payloads using the default JSON content profile in the ASM security policy. A remote attacker can pass specially crafted input to the system and crash the BIG-IP ASM bd process.