7.8
CVE-2021-23022
- EPSS 0.14%
- Veröffentlicht 10.06.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:10
- Quelle f5sirt@f5.com
- CVE-Watchlists
- Unerledigt
On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, the BIG-IP Edge Client Windows Installer Service's temporary folder has weak file and folder permissions. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
F5 ≫ Big-ip Access Policy Manager Version >= 11.6.1 <= 11.6.5
F5 ≫ Big-ip Access Policy Manager Version >= 12.1.0 <= 12.1.6
F5 ≫ Big-ip Access Policy Manager Client Version >= 7.1.6 <= 7.1.9.9
F5 ≫ Big-ip Access Policy Manager Client Version >= 7.2.1 < 7.2.1.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.343 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.