In all versions before 7.2.1.4, when proxy settings are configured in the network access resource of a BIG-IP APM system, connecting BIG-IP Edge Client on Mac and Windows is vulnerable to a DNS rebinding attack. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
2022-01-25T20:15:10.053
2024-11-21T06:47:50.853
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | f5 | big-ip_access_policy_manager | ≤ 11.6.5 | Yes |
Application | f5 | big-ip_access_policy_manager | ≤ 12.1.6 | Yes |
Application | f5 | big-ip_access_policy_manager | ≤ 13.1.4 | Yes |
Application | f5 | big-ip_access_policy_manager | ≤ 14.1.4 | Yes |
Application | f5 | big-ip_access_policy_manager | ≤ 15.1.5 | Yes |
Application | f5 | big-ip_access_policy_manager | ≤ 16.1.2 | Yes |
Application | f5 | big-ip_access_policy_manager_client | ≤ 7.1.9 | Yes |
Application | f5 | big-ip_access_policy_manager_client | ≤ 7.2.1.3 | Yes |