2 results (0.002 seconds)

CVSS: 6.7EPSS: 0%CPEs: 4EXPL: 0

14 Feb 2024 — BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced shell (bash) can execute arbitrary commands with a specially crafted command string. This vulnerability is due to an incomplete fix for CVE-2020-5873. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated Los administradores de recursos y administradores de certificados de BIG-IP o BIG-IQ que tienen acceso a la utilidad d... • https://my.f5.com/manage/s/article/K98606833 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 9.0EPSS: 34%CPEs: 1EXPL: 4

05 May 2014 — F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter in a request to the user's page in mgmt/shared/authz/users/. F5 BIG-IQ 4.1.0.2013.0 permite a usuarios remotos autenticados cambiar la contraseña de usuarios arbitrarios a través del parámetro name en una solicitud hacia la página del usuario en mgmt/shared/authz/users/. • https://www.exploit-db.com/exploits/33143 • CWE-255: Credentials Management Errors •