F5 BIG-IQ Centralized Management 7.1.0.1

CPE Details

F5 BIG-IQ Centralized Management 7.1.0.1
7.1.0.1
2020-11-09
16h50 +00:00
2020-11-09
16h50 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:f5:big-iq_centralized_management:7.1.0.1:*:*:*:*:*:*:*

Informations

Vendor

f5

Product

big-iq_centralized_management

Version

7.1.0.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-23006 2021-03-31 15h44 +00:00 On all 7.x and 6.x versions (fixed in 8.0.0), undisclosed BIG-IQ pages have a reflected cross-site scripting vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
6.1
Medium
CVE-2021-23005 2021-03-31 15h41 +00:00 On all 7.x and 6.x versions (fixed in 8.0.0), when using a Quorum device for BIG-IQ high availability (HA) for automatic failover, BIG-IQ does not make use of Transport Layer Security (TLS) with the Corosync protocol. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
9.1
Critical
CVE-2021-22997 2021-03-31 15h35 +00:00 On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ HA ElasticSearch service does not implement any form of authentication for the clustering transport services, and all data used by ElasticSearch for transport is unencrypted. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
7.5
High
CVE-2021-22996 2021-03-31 15h34 +00:00 On all 7.x versions (fixed in 8.0.0), when set up for auto failover, a BIG-IQ Data Collection Device (DCD) cluster member that receives an undisclosed message may cause the corosync process to abort. This behavior may lead to a denial-of-service (DoS) and impact the stability of a BIG-IQ high availability (HA) cluster. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
7.5
High
CVE-2021-22986 2021-03-31 14h04 +00:00 On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
9.8
Critical