Security Advisory

CVE-2023-29240

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-05-03 14:35:03
Last updated 2025-09-18 19:48:26
Assigner f5
State PUBLISHED

Description

An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.