#VU51392 Cleartext transmission of sensitive information in BIG-IQ Centralized Management - CVE-2021-23005
Published: March 11, 2021
BIG-IQ Centralized Management
F5 Networks
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to software uses insecure communication channel to transmit sensitive information. When using a Quorum device for BIG-IQ high availability (HA) for automatic failover, BIG-IQ does not make use of Transport Layer Security (TLS) with the Corosync protocol. A remote attacker with ability to intercept network traffic can gain access to sensitive data.