A syntax construct inside the TCL language is allowing injection attacks to occur. Because it’s in the language itself, it cannot be patched. The mitigation is that expressions in Tcl should always be “braced” This may be as simple as enclosing the expression in curly braces ‘{}’ A Shodan search turned up 300,000 worldwide active BIG-IP implementations with 60% of them in the U.S. There’s the potential for big stuff here, says Larry Loeb.”]
Source: https://www.darkreading.com/abtv/a-brace-helps-to-balance-the-load/a/d-id/753431

