CVE-2016-5021 - CVE House
Back to Database
Status published Medium CVE-2016-5021

The iControl REST service in F5 BIG-IP LTM, AAM, AFM,...

Vulnerability Description

The iControl REST service in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF3; BIG-IP DNS 12.x before 12.0.0 HF3; BIG-IP GTM 11.5.x before 11.5.4 and 11.6.x before 11.6.1; BIG-IQ Cloud and Security 4.0.0 through 4.5.0; BIG-IQ Device 4.2.0 through 4.5.0; BIG-IQ ADC 4.5.0; BIG-IQ Centralized Management 4.6.0; and BIG-IQ Cloud and Orchestration 1.0.0 allows remote authenticated administrators to obtain sensitive information via unspecified vectors.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-5021

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

big-iq application delivery controller, big-iq cloud and orchestration, big-ip application acceleration manager, big-ip access policy manager, big-ip local traffic manager, big-ip global traffic manager, big-iq security, big-iq cloud, big-ip application security manager, big-iq centralized management, big-ip domain name system, big-ip analytics, big-ip link controller, big-ip policy enforcement manager, big-iq device, big-ip advanced firewall manager
Vulnerable Versions:
4.5.0, 1.0.0, 11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.6.0, 12.0.0, 4.0.0, 4.1.0, 4.2.0, 4.3.0, 4.4.0, 4.6.0

Timeline

Official Publish: June 24th, 2016
Last Modified: August 6th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.