Vulnerabilities > F5 > BIG IQ Centralized Management > 7.1.0.1

DATE CVE VULNERABILITY TITLE RISK
2021-03-31 CVE-2021-23006 Cross-site Scripting vulnerability in F5 Big-Iq Centralized Management
On all 7.x and 6.x versions (fixed in 8.0.0), undisclosed BIG-IQ pages have a reflected cross-site scripting vulnerability.
network
f5 CWE-79
4.3
2021-03-31 CVE-2021-23005 Unspecified vulnerability in F5 Big-Iq Centralized Management
On all 7.x and 6.x versions (fixed in 8.0.0), when using a Quorum device for BIG-IQ high availability (HA) for automatic failover, BIG-IQ does not make use of Transport Layer Security (TLS) with the Corosync protocol.
network
low complexity
f5
6.4
2021-03-31 CVE-2021-22997 Missing Authentication for Critical Function vulnerability in F5 Big-Iq Centralized Management
On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ HA ElasticSearch service does not implement any form of authentication for the clustering transport services, and all data used by ElasticSearch for transport is unencrypted.
network
low complexity
f5 CWE-306
5.0
2021-03-31 CVE-2021-22996 Unspecified vulnerability in F5 Big-Iq Centralized Management 7.0.0/7.1.0/7.1.0.1
On all 7.x versions (fixed in 8.0.0), when set up for auto failover, a BIG-IQ Data Collection Device (DCD) cluster member that receives an undisclosed message may cause the corosync process to abort.
network
low complexity
f5
5.0
2021-03-31 CVE-2021-22986 Server-Side Request Forgery (SSRF) vulnerability in F5 products
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability.
network
low complexity
f5 CWE-918
critical
10.0