Description
Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.From K23203045:If an attacker has network access to the BIG-IP Advanced WAF and ASM devices and has authenticated with guest privileges, the attacker could upload files to the BIG-IP Advanced WAF and ASM devices via the REST API. This may allow the attacker to upload and overwrite a limited set of files on BIG-IP Advanced WAF and ASM systems.
Solution(s)
f5-big-ip-upgrade-latest
Referenceshttps://support.f5.com/csp/article/K23203045CVE-2021-23014