CVE-2026-41954
Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Faiblesse
Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Produits concernés
- f5 big-ip_access_policy_manager
- f5 big-ip_advanced_firewall_manager
- f5 big-ip_advanced_web_application_firewall
- f5 big-ip_analytics
- f5 big-ip_application_acceleration_manager
- f5 big-ip_application_security_manager
- f5 big-ip_application_visibility_and_reporting
- f5 big-ip_automation_toolchain
Références
Trouvez la faille avant un attaquant.
Connectez-vous avec GitHub et lancez votre premier audit en moins d'une minute. L'offre gratuite ne nécessite aucune carte bancaire.