CVE-2024-27202

Severity
4.7MEDIUM
EPSS
0.5%
top 34.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 8

Description

A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 1.6 | Impact: 2.7

Affected Packages22 packages

CVEListV5f5/big-ip17.1.017.1.1.3+2
NVDf5/big-ip_websafe15.1.015.1.10.4+2
NVDf5/big-ip_analytics15.1.015.1.10.4+2
NVDf5/big-ip_edge_gateway15.1.015.1.10.4+2
NVDf5/big-ip_webaccelerator15.1.015.1.10.4+2

🔴Vulnerability Details

2
GHSA
GHSA-frv4-f3cq-3x3v: A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run2024-05-08
CVEList
BIG-IP TMUI XSS vulnerability2024-05-08

📋Vendor Advisories

1
F5
CVE-2024-27202: A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utilit...2024-05-08
CVE-2024-27202 (MEDIUM CVSS 4.7) | A DOM-based cross-site scripting (X | cvebase.io