CVE-2021-22980
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Edge Client version 7.2.x before 7.2.1.1, 7.1.9.x before 7.1.9.8, and 7.1.x-7.1.8.x before 7.1.8.5, an untrusted search path vulnerability in the BIG-IP APM Client Troubleshooting Utility (CTU) for Windows could allow an attacker to load a malicious DLL library from its current directory. User interaction is required to exploit this vulnerability in that the victim must run this utility on the Windows system. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
En Edge Client versiones 7.2.x anteriores a 7.2.1.1, versiones 7.1.9.x anteriores 7.1.9.8 y versiones 7.1.x-7.1.8.x anteriores a 7.1.8.5, una vulnerabilidad de ruta de búsqueda no confiable en BIG-IP APM Client Troubleshooting Utility (CTU) para Windows, podría permitir a un atacante cargar una biblioteca DLL maliciosa desde su directorio actual. Es requerida una interacción del usuario para explotar esta vulnerabilidad, ya que la víctima debe ejecutar esta utilidad en el sistema Windows. Nota: No son evaluadas las versiones de software que han alcanzado End of Software Development (EoSD)
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-06 CVE Reserved
- 2021-02-12 CVE Published
- 2023-10-29 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-426: Untrusted Search Path
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.f5.com/csp/article/K29282483 | 2021-02-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
F5 Search vendor "F5" | Access Policy Manager Clients Search vendor "F5" for product "Access Policy Manager Clients" | >= 7.1.5 < 7.1.8.5 Search vendor "F5" for product "Access Policy Manager Clients" and version " >= 7.1.5 < 7.1.8.5" | - |
Affected
| ||||||
F5 Search vendor "F5" | Access Policy Manager Clients Search vendor "F5" for product "Access Policy Manager Clients" | >= 7.1.9 < 7.1.9.8 Search vendor "F5" for product "Access Policy Manager Clients" and version " >= 7.1.9 < 7.1.9.8" | - |
Affected
| ||||||
F5 Search vendor "F5" | Access Policy Manager Clients Search vendor "F5" for product "Access Policy Manager Clients" | >= 7.2.1 < 7.2.1.1 Search vendor "F5" for product "Access Policy Manager Clients" and version " >= 7.2.1 < 7.2.1.1" | - |
Affected
| ||||||
F5 Search vendor "F5" | Big-ip Access Policy Manager Search vendor "F5" for product "Big-ip Access Policy Manager" | >= 11.6.1 <= 11.6.5 Search vendor "F5" for product "Big-ip Access Policy Manager" and version " >= 11.6.1 <= 11.6.5" | - |
Affected
| ||||||
F5 Search vendor "F5" | Big-ip Access Policy Manager Search vendor "F5" for product "Big-ip Access Policy Manager" | >= 12.1.0 <= 12.1.5 Search vendor "F5" for product "Big-ip Access Policy Manager" and version " >= 12.1.0 <= 12.1.5" | - |
Affected
| ||||||
F5 Search vendor "F5" | Big-ip Access Policy Manager Search vendor "F5" for product "Big-ip Access Policy Manager" | >= 13.1.0 < 13.1.3.6 Search vendor "F5" for product "Big-ip Access Policy Manager" and version " >= 13.1.0 < 13.1.3.6" | - |
Affected
| ||||||
F5 Search vendor "F5" | Big-ip Access Policy Manager Search vendor "F5" for product "Big-ip Access Policy Manager" | >= 14.1.0 <= 14.1.3 Search vendor "F5" for product "Big-ip Access Policy Manager" and version " >= 14.1.0 <= 14.1.3" | - |
Affected
| ||||||
F5 Search vendor "F5" | Big-ip Access Policy Manager Search vendor "F5" for product "Big-ip Access Policy Manager" | >= 15.1.0 <= 15.1.2 Search vendor "F5" for product "Big-ip Access Policy Manager" and version " >= 15.1.0 <= 15.1.2" | - |
Affected
| ||||||
F5 Search vendor "F5" | Big-ip Access Policy Manager Search vendor "F5" for product "Big-ip Access Policy Manager" | >= 16.0.0 < 16.0.1.1 Search vendor "F5" for product "Big-ip Access Policy Manager" and version " >= 16.0.0 < 16.0.1.1" | - |
Affected
|