cbcvebase.
CVE-2021-23046
published 2021-09-14

CVE-2021-23046: On all versions of Guided Configuration before 8.0.0, when a configuration that contains secure properties is created and deployed from Access Guided…

PriorityP425medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.77%
51.4th percentile
On all versions of Guided Configuration before 8.0.0, when a configuration that contains secure properties is created and deployed from Access Guided Configuration (AGC), secure properties are logged in restnoded logs. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected

8 ranges
VendorProductVersion rangeFixed in
f5big-ip_access_policy_manager13.1.0 – 13.1.4
f5big-ip_access_policy_manager14.1.0 – 14.1.4
f5big-ip_access_policy_manager15.1.0 – 15.1.3
f5big-ip_access_policy_manager>= 16.0.0 < 16.1.016.1.0
f5big-ip_apm
f5big-ip_guided_configuration< 8.0.08.0.0
f5big-ip_guided_configuration
f5big-ip_guided_configuration

CVSS provenance

nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.