F5 BIG-IP APM AD (Active Directory) Authentication Flaw Bypassed using a Spoofed AS-REP

Cybersecurity researchers on Wednesday disclosed a new bypass vulnerability (CVE-2021-23008) in the Kerberos Key Distribution Center (KDC) security feature impacting F5 Big-IP application delivery services. “BIG-IP APM AD (Active Directory) authentication can be bypassed using a spoofed AS-REP (Kerberos Authentication Service Response) response sent over a hijacked KDC (Kerberos Key Distribution Center) connection, or from […] The post F5 BIG-IP APM AD (Active Directory) Authentication Flaw Bypassed using a Spoofed AS-REP appeared first on Cyber Security News.
http://dlvr.it/RykzKk

No comments:

Post a Comment