Description
Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.From K66851119:An attacker may exploit this vulnerability using a crafted URL to a reflected cross-site scripting (XSS) vulnerability in an undisclosed page of the Configuration utility, leading to a complete compromise of the BIG-IP system if the victim user is granted the admin role.
Solution(s)
f5-big-ip-upgrade-latest
Referenceshttps://support.f5.com/csp/article/K02566623https://support.f5.com/csp/article/K66851119CVE-2021-22994