{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"BIG-IP (LTM, AAM, Advanced WAF, AFM, Analytics, APM, ASM, DDHD, DNS, FPS, GTM, Link Controller, PEM, SSLO) versions ant\u00e9rieures \u00e0 15.1.2","product":{"name":"BIG-IP","vendor":{"name":"F5","scada":false}}},{"description":"BIG-IP (LTM, AAM, Advanced WAF, AFM, Analytics, APM, ASM, DDHD, DNS, FPS, GTM, Link Controller, PEM, SSLO) versions ant\u00e9rieures \u00e0 13.1.3.6","product":{"name":"BIG-IP","vendor":{"name":"F5","scada":false}}},{"description":"BIG-IP (LTM, AAM, Advanced WAF, AFM, Analytics, APM, ASM, DDHD, DNS, FPS, GTM, Link Controller, PEM, SSLO) versions ant\u00e9rieures \u00e0 14.1.3.1 (cette version est affect\u00e9e par une autre vuln\u00e9rabilit\u00e9, cf. l'avis \u00e9diteur)","product":{"name":"BIG-IP","vendor":{"name":"F5","scada":false}}},{"description":"BIG-IP (LTM, AAM, Advanced WAF, AFM, Analytics, APM, ASM, DDHD, DNS, FPS, GTM, Link Controller, PEM, SSLO) versions ant\u00e9rieures \u00e0 11.6.5.3","product":{"name":"BIG-IP","vendor":{"name":"F5","scada":false}}},{"description":"BIG-IP (LTM, AAM, Advanced WAF, AFM, Analytics, APM, ASM, DDHD, DNS, FPS, GTM, Link Controller, PEM, SSLO) versions ant\u00e9rieures \u00e0 16.1.0","product":{"name":"BIG-IP","vendor":{"name":"F5","scada":false}}},{"description":"BIG-IP (LTM, AAM, Advanced WAF, AFM, Analytics, APM, ASM, DDHD, DNS, FPS, GTM, Link Controller, PEM, SSLO) versions ant\u00e9rieures \u00e0 12.1.5.3 (cette version est affect\u00e9e par une autre vuln\u00e9rabilit\u00e9, cf. l'avis \u00e9diteur)","product":{"name":"BIG-IP","vendor":{"name":"F5","scada":false}}},{"description":"BIG-IP (APM) versions 12.1.x et 11.6.x (F5 ne corrigera pas la vuln\u00e9rabilit\u00e9 CVE-2020-27729 pour ces versions)","product":{"name":"BIG-IP","vendor":{"name":"F5","scada":false}}}],"affected_systems_content":null,"content":"## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des\ncorrectifs (cf. section Documentation).\n","cves":[{"name":"CVE-2021-23003","url":"https://www.cve.org/CVERecord?id=CVE-2021-23003"},{"name":"CVE-2020-27729","url":"https://www.cve.org/CVERecord?id=CVE-2020-27729"},{"name":"CVE-2021-22989","url":"https://www.cve.org/CVERecord?id=CVE-2021-22989"}],"links":[],"reference":"CERTFR-2021-AVI-509","revisions":[{"description":"Version initiale","revision_date":"2021-07-08T00:00:00.000000"}],"risks":[{"description":"D\u00e9ni de service \u00e0 distance"},{"description":"Contournement de la politique de s\u00e9curit\u00e9"}],"summary":"De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans F5 BIG-IP. Elles\npermettent \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance et\nun contournement de la politique de s\u00e9curit\u00e9.\n","title":"Multiples vuln\u00e9rabilit\u00e9s dans F5 BIG-IP","vendor_advisories":[{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 F5 K43470422 du 10 mars 2021","url":"https://support.f5.com/csp/article/K43470422"},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 F5 K15310332 du 17 d\u00e9cembre 2020","url":"https://support.f5.com/csp/article/K15310332"},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 F5 K56142644 du 10 mars 2021","url":"https://support.f5.com/csp/article/K56142644"}]}
