cbcvebase.
CVE-2021-23015
published 2021-05-10

CVE-2021-23015: On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when running in Appliance Mode, an authenticated…

high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
On BIG-IP 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.0.8 through 13.1.3.6, and all versions of 16.0.x, when running in Appliance Mode, an authenticated user assigned the 'Administrator' role may be able to bypass Appliance Mode restrictions utilizing undisclosed iControl REST endpoints. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected

72 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip_aam
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager>= 13.1.0 < 13.1.413.1.4
f5big-ip_access_policy_manager>= 14.1.0 < 14.1.414.1.4
f5big-ip_access_policy_manager>= 15.1.0 < 15.1.315.1.3
f5big-ip_access_policy_manager>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_advanced_firewall_manager>= 13.1.0 < 13.1.413.1.4
f5big-ip_advanced_firewall_manager>= 14.1.0 < 14.1.414.1.4
f5big-ip_advanced_firewall_manager>= 15.1.0 < 15.1.315.1.3
f5big-ip_advanced_firewall_manager>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_advanced_waf
f5big-ip_advanced_web_application_firewall>= 13.1.0 < 13.1.413.1.4
f5big-ip_advanced_web_application_firewall14.1.0 – 14.1.4
f5big-ip_advanced_web_application_firewall>= 15.1.0 < 15.1.315.1.3
f5big-ip_advanced_web_application_firewall>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics>= 13.1.0 < 13.1.413.1.4
f5big-ip_analytics>= 14.1.0 < 14.1.414.1.4
f5big-ip_analytics>= 15.1.0 < 15.1.315.1.3
f5big-ip_analytics>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_apm
f5big-ip_application_acceleration_manager>= 13.1.0 < 13.1.413.1.4
f5big-ip_application_acceleration_manager>= 14.1.0 < 14.1.414.1.4
f5big-ip_application_acceleration_manager>= 15.1.0 < 15.1.315.1.3