Executive brief
The F5 BIG-IP Traffic Management User Interface (TMUI), also known as the Configuration utility, contains a remote code execution vulnerability due to improper limitation of a pathname to a restricted directory (path traversal). This allows unauthenticated attackers with network access to the TMUI to execute arbitrary system commands, create or delete files, and disable services.
Affected products
- F5 BIG-IP 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, 11.6.1-11.6.5.1
Timeline
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed