Description
Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view adjacent network information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
BIG-IP
BIG-IP
BIG-IQ
BIG-IQ
Problem types
CWE-732 Incorrect Permission Assignment for Critical Resource
Product status
21.1.0 (custom) before *
21.0.0 (custom) before 21.0.0.2
17.5.0 (custom) before 17.5.1.6
17.1.0 (custom) before 17.1.3.2
16.1.0 (custom) before *
8.4.0 (custom) before *
Credits
F5
References
my.f5.com/manage/s/article/K000161018