CVE-2021-23053
published 2021-09-14CVE-2021-23053: On version 15.1.x before 15.1.3, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6, when the brute force protection feature of BIG-IP Advanced WAF or BIG-IP…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.92%
56.2th percentile
On version 15.1.x before 15.1.3, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6, when the brute force protection feature of BIG-IP Advanced WAF or BIG-IP ASM is enabled on a virtual server and the virtual server is under brute force attack, the MySQL database may run out of disk space due to lack of row limit on undisclosed tables in the MYSQL database. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_advanced_waf | — | — |
| f5 | big-ip_advanced_web_application_firewall | >= 13.1.0 < 13.1.3.6 | 13.1.3.6 |
| f5 | big-ip_advanced_web_application_firewall | >= 14.1.0 < 14.1.3.1 | 14.1.3.1 |
| f5 | big-ip_advanced_web_application_firewall | >= 15.1.0 < 15.1.3 | 15.1.3 |
| f5 | big-ip_application_security_manager | >= 13.1.0 < 13.1.3.6 | 13.1.3.6 |
| f5 | big-ip_application_security_manager | >= 14.1.0 < 14.1.3.1 | 14.1.3.1 |
| f5 | big-ip_application_security_manager | >= 15.1.0 < 15.1.3 | 15.1.3 |
| f5 | big-ip_asm | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6ccx-cmhg-89c5: On version 15
ghsa_unreviewed·2022-05-24
CVE-2021-23053 [MEDIUM] CWE-400 GHSA-6ccx-cmhg-89c5: On version 15
On version 15.1.x before 15.1.3, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6, when the brute force protection feature of BIG-IP Advanced WAF or BIG-IP ASM is enabled on a virtual server and the virtual server is under brute force attack, the MySQL database may run out of disk space due to lack of row limit on undisclosed tables in the MYSQL database. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
F5
CVE-2021-23053: On version 15
vendor_f5·2021-09-14·CVSS 5.3
CVE-2021-23053 [MEDIUM] CWE-400 CVE-2021-23053: On version 15
CVE-2021-23053: On version 15
On version 15.1.x before 15.1.3, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6, when the brute force protection feature of BIG-IP Advanced WAF or BIG-IP ASM is enabled on a virtual server and the virtual server is under brute force attack, the MySQL database may run out of disk space due to lack of row limit on undisclosed tables in the MYSQL database. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: BIG-IP ASM, BIG-IP Advanced WAF
Affected Versions: 13.1.0 - 13.1.3.6; 14.1.0 - 14.1.3.1; 15.1.0 - 15.1.3
F5 Advisory Articles: K36942191
F5 References: https://support.f5.com/csp/article/K36942191
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-09-14
Published