important · Edge — BIG-IP
Attackers are exploiting a pre-authentication header overflow for code execution on configured F5 BIG-IP APM gateways.
Affects
F5 BIG-IP Access Policy Manager, an application-delivery and remote-access appliance deployed at enterprise network edges.
Only virtual servers combining an APM policy with an OAuth authorization-server profile expose the path. An oversized Bearer header can corrupt an adjacent callback and reach command execution through a ROP chain and the tmm.finish hook.
Detail and 2 sources
F5 published fixes, but it continues to accept pre-fix software images.