Security Advisory
CVE-2023-29240
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.