Elektrine lite

← Feed

@fuzzyfuzzyfungus@cyberplace.social

2026-09-22 15:17 UTC

@cR0w@infosec.exchange Is there some moderately esoteric architectural arrangement that allows that remotely executed code to run on something that isn't management-related; or is "there is no control plane exposure" grotesque sophistry?

Replies (1)

  • @cR0w@infosec.exchange 2026-09-22 15:21

    @fuzzyfuzzyfungus@cyberplace.social When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server My understanding is that the interface exposed with an access policy and OAuth profile is vulnerable, regardless of where the management interfaces are. So if your APM is in front of an application and using an OAuth profile for access control, it would apparently be vulnerable. I think they specified "no control plane exposure" so people didn't assume they're protected just because their management interfaces aren't exposed. Which is such a common approach to these vulns. This adds urgency.

    Open ##4806528