Showing 2 vulnerabilities on this page for BIG-IP Configuration Utility

Signals CISA KEV Ransomware Nuclei
F5 vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

BIG-IP Configuration utility authenticated SQL injection vulnerability

An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CWE-89Oct 26, 2023
CVSS8.8v3.1EPSS4.47%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

BIG-IP Configuration utility unauthenticated remote code execution vulnerability

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CWE-288CWE-306Oct 26, 20231 related artifact
CVSS9.8v3.1EPSS96.5%PoCs10SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX