BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced shell (bash) can execute arbitrary commands with a specially crafted command string. This vulnerability is due to an incomplete fix for CVE-2020-5873.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
References
Link | Resource |
---|---|
https://my.f5.com/manage/s/article/K98606833 |
Configurations
No configuration.
History
No history.
Information
Published : 2024-02-14 17:15
Updated : 2024-02-14 18:04
NVD link : CVE-2024-21782
Mitre link : CVE-2024-21782
CVE.ORG link : CVE-2024-21782
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')