« Volver al listado

CVE-2021-22993

Estado: ModificadaAlta (8.8)—

On BIG-IP Advanced WAF and BIG-IP ASM versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, DOM-based XSS on DoS Profile properties page. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-22993",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "f5sirt@f5.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "BIG-IP Advanced WAF and BIG-IP ASM",
          "versions": [
            {
              "status": "affected",
              "version": "16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-03-31T18:15:14.847",
  "references": [
    {
      "url": "https://support.f5.com/csp/article/K55237223",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "f5sirt@f5.com"
    },
    {
      "url": "https://support.f5.com/csp/article/K55237223",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "On BIG-IP Advanced WAF and BIG-IP ASM versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, DOM-based XSS on DoS Profile properties page. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated."
    },
    {
      "lang": "es",
      "value": "En BIG-IP Advanced WAF y BIG-IP ASM versiones 16.0.x anteriores de 16.0.1.1, versiones 15.1.x anteriores a 15.1.2, versiones 14.1.x anteriores a 14.1.3.1, versiones 13.1.x anteriores a 13.1.3.6 y versiones 12.1.x anteriores a 12.1 .5.3, un XSS basado en DOM en la página de propiedades de DoS Profile. Nota: No se evalúan las versiones de software que han alcanzado End of Software Development (EoSD)."
    }
  ],
  "lastModified": "2026-06-17T03:38:10.367",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12A27D41-6DEC-4887-A9A0-FE5AAD01FA98",
              "versionEndExcluding": "12.1.5.3",
              "versionStartIncluding": "12.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "39DDA652-065C-4AF9-A014-E0DAFF60B61B",
              "versionEndExcluding": "13.1.3.6",
              "versionStartIncluding": "13.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF641654-BDC0-4483-B6BA-D5566427E5C5",
              "versionEndExcluding": "14.1.3.1",
              "versionStartIncluding": "14.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E0224A2-82E3-459A-8BEC-A2FC7B526230",
              "versionEndExcluding": "15.1.2",
              "versionStartIncluding": "15.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6B9117DA-6AA9-4704-A092-B1D426E6370D",
              "versionEndExcluding": "16.0.1.1",
              "versionStartIncluding": "16.0.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A921F4E5-6BA7-4978-B47E-D1B173FF493F",
              "versionEndExcluding": "12.1.5.3",
              "versionStartIncluding": "12.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2BF4F8C6-1C43-4A54-9FD6-011253744FC8",
              "versionEndExcluding": "13.1.3.6",
              "versionStartIncluding": "13.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0B1C52A-361A-46BD-9531-96C69F011EBC",
              "versionEndExcluding": "14.1.3.1",
              "versionStartIncluding": "14.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24B9D974-3C1E-4467-A844-F9FDCD39A7FD",
              "versionEndExcluding": "15.1.2",
              "versionStartIncluding": "15.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7BB77EFF-A064-4475-A93C-5D5BA9313724",
              "versionEndExcluding": "16.0.1.1",
              "versionStartIncluding": "16.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "f5sirt@f5.com"
}