vendor:
Big-IP Services
by:
Carlos E. Vieira
9.8
CVSS
CRITICAL
Local File Inclusion
22
CWE
Product Name: Big-IP Services
Affected Version From: <= 13.1.3
Affected Version To: <= 13.1.3
Patch Exists: YES
Related CWE: CVE-2020-5902
CPE: a:f5:big-ip_services
Other Scripts:
N/A
Platforms Tested: BIG-IP 13.1.3 Build 0.0.6
2019
F5 Big-IP 13.1.3 Build 0.0.6 – Local File Inclusion
F5 Big-IP 13.1.3 Build 0.0.6 is vulnerable to Local File Inclusion. An attacker can exploit this vulnerability to read sensitive files from the server. This vulnerability is due to improper validation of user-supplied input by the affected software. An attacker can exploit this vulnerability by sending a specially crafted request to the affected software.
Mitigation:
F5 has released a security advisory and software updates to address this vulnerability. Users are advised to apply the necessary updates.