CVE-2021-23002
published 2021-03-31CVE-2021-23002: When using BIG-IP APM 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, or all 12.1.x and 11.6.x versions or Edge…
PriorityP420medium4.5CVSS 3.1
AVAACLPRHUINSUCHINAN
EPSS
0.34%
26.1th percentile
When using BIG-IP APM 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, or all 12.1.x and 11.6.x versions or Edge Client versions 7.2.1.x before 7.2.1.1, 7.1.9.x before 7.1.9.8, or 7.1.8.x before 7.1.8.5, the session ID is visible in the arguments of the f5vpn.exe command when VPN is launched from the browser on a Windows system. Addressing this issue requires both the client and server fixes. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | access_policy_manager_clients | — | — |
| f5 | access_policy_manager_clients | >= 7.1.5 < 7.1.8.5 | 7.1.8.5 |
| f5 | access_policy_manager_clients | >= 7.1.9 < 7.1.9.8 | 7.1.9.8 |
| f5 | access_policy_manager_clients | >= 7.2.1 < 7.2.1.1 | 7.2.1.1 |
| f5 | big-ip_access_policy_manager | 11.6.1 – 11.6.5 | — |
| f5 | big-ip_access_policy_manager | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_access_policy_manager | >= 13.1.0 < 13.1.3.6 | 13.1.3.6 |
| f5 | big-ip_access_policy_manager | >= 14.1.0 < 14.1.4 | 14.1.4 |
| f5 | big-ip_access_policy_manager | >= 15.1.0 < 15.1.2.1 | 15.1.2.1 |
| f5 | big-ip_access_policy_manager | >= 16.0.0 < 16.0.1.1 | 16.0.1.1 |
| f5 | big-ip_apm | — | — |
CVSS provenance
nvdv3.14.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.7LOWAV:A/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4vpw-2c2c-m7m5: When using BIG-IP APM 16
ghsa_unreviewed·2022-05-24
CVE-2021-23002 [MEDIUM] GHSA-4vpw-2c2c-m7m5: When using BIG-IP APM 16
When using BIG-IP APM 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, or all 12.1.x and 11.6.x versions or Edge Client versions 7.2.1.x before 7.2.1.1, 7.1.9.x before 7.1.9.8, or 7.1.8.x before 7.1.8.5, the session ID is visible in the arguments of the f5vpn.exe command when VPN is launched from the browser on a Windows system. Addressing this issue requires both the client and server fixes. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
F5
CVE-2021-23002: When using BIG-IP APM 16
vendor_f5·2021-03-31·CVSS 4.5
CVE-2021-23002 [MEDIUM] CVE-2021-23002: When using BIG-IP APM 16
CVE-2021-23002: When using BIG-IP APM 16
When using BIG-IP APM 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, or all 12.1.x and 11.6.x versions or Edge Client versions 7.2.1.x before 7.2.1.1, 7.1.9.x before 7.1.9.8, or 7.1.8.x before 7.1.8.5, the session ID is visible in the arguments of the f5vpn.exe command when VPN is launched from the browser on a Windows system. Addressing this issue requires both the client and server fixes. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Affected Products: Access Policy Manager Clients, BIG-IP APM
Affected Versions: 11.6.1 - 11.6.5; 12.1.0 - 12.1.5; 13.1.0 - 13.1.3.6; 14.1.0 - 14.1.4; 15.1.0 - 15.1.2.1; 16.0.0 - 16.0.1.1; 7.1.5 - 7.1.8.5; 7.1.9 - 7.1.9.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-03-31
Published