Rapid7 Vulnerability & Exploit Database

F5 Networks: K63497634 (CVE-2021-22979): BIG-IP FPS XSS vulnerability CVE-2021-22979

Back to Search

F5 Networks: K63497634 (CVE-2021-22979): BIG-IP FPS XSS vulnerability CVE-2021-22979

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
02/10/2021
Created
02/13/2021
Added
02/11/2021
Modified
03/08/2021

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.

From K63497634:

Impact

A remote attacker may potentially exploit this vulnerability by sending a specific crafted URL that includes the specific target host name and malicious HTML or JavaScript code to a BIG-IP Configuration utility user, which is then reflected back to the victim and executed by the web browser. If the exploit is successful, an attacker can run JavaScript in the context of the currently logged-in user. In the case of an administrative user with access to the Advanced Shell (bash), successful exploitation of this vulnerability can be leveraged to completely compromise the BIG-IP system through remote code execution.

Solution(s)

  • f5-big-ip-upgrade-latest

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;