CyberRota Analysis
AI-GeneratedThe vulnerability affects BIG-IP systems configured with an APM access policy and an OAuth profile, allowing unauthenticated attackers to execute remote code through malicious traffic. This critical issue poses a significant risk, particularly for systems operating in Appliance mode, as it enables exploitation without requiring authentication. Organizations using BIG-IP should prioritize immediate remediation to mitigate potential security breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Related CVEs
Other vulnerabilities affecting the same vendor(s)