HTTP: F5 BIG-IP and BIG-IQ iControl iControlPortal.cgi Format String
This signature detects attempts to exploit a known vulnerability against F5 BIG-IP and BIG-IQ iControl. A successful attack can lead to arbitrary code execution.
Extended Description
A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appliance mode BIG-IP, a successful exploit of this vulnerability can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products
F5 big-ip_access_policy_manager
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
F5