Vulnerability Details CVE-2021-23005
On all 7.x and 6.x versions (fixed in 8.0.0), when using a Quorum device for BIG-IQ high availability (HA) for automatic failover, BIG-IQ does not make use of Transport Layer Security (TLS) with the Corosync protocol. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 63.5%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 6.4
Products affected by CVE-2021-23005
-
cpe:2.3:a:f5:big-iq_centralized_management:6.0.0
-
cpe:2.3:a:f5:big-iq_centralized_management:6.0.1
-
cpe:2.3:a:f5:big-iq_centralized_management:6.1.0
-
cpe:2.3:a:f5:big-iq_centralized_management:7.0.0
-
cpe:2.3:a:f5:big-iq_centralized_management:7.1.0
-
cpe:2.3:a:f5:big-iq_centralized_management:7.1.0.1