cbcvebase.
CVE-2023-29240
published 2023-05-03

CVE-2023-29240: An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint. Note: Software…

PriorityP432medium5.4CVSS 3.1
AVNACLPRLUINSUCNILAL
EPSS
0.40%
32.8th percentile
An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected

4 ranges
VendorProductVersion rangeFixed in
f5big-iq
f5big-iq>= 8.0.0 < 8.3.08.3.0
f5big-iq_centralized_management>= 8.0.0 < 8.3.08.3.0
f5icontrol_rest
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.