Last Modified: Jan 04, 2023
Affected Product:
See more info
F5OS Velos
Known Affected Versions:
1.0.0, 1.0.0-420.0, 1.0.1, 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.2.0, 1.2.1, 1.2.2, 1.3.0, 1.3.1, 1.3.2
Opened: Nov 04, 2022
Severity: 3-Major
On add server screen of radius server group, the secret key field is not a mandatory field, which allows the user to add a server without any secret key.
If no secret key is provided by user as the field is not mandatory, the timeout value is read as a secret key for server, which is not correct.
User created a server group of type radius and tries to add a server in that group.
User can provide a secret key even though it is not mandatory on the webUI.
None