CVE-2026-41954
Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Fraqueza
Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Produtos afetados
- f5 big-ip_access_policy_manager
- f5 big-ip_advanced_firewall_manager
- f5 big-ip_advanced_web_application_firewall
- f5 big-ip_analytics
- f5 big-ip_application_acceleration_manager
- f5 big-ip_application_security_manager
- f5 big-ip_application_visibility_and_reporting
- f5 big-ip_automation_toolchain
Referências
Encontre a falha antes de um atacante.
Entre com o GitHub e rode sua primeira auditoria em menos de um minuto. O plano gratuito não exige cartão de crédito.