QID 375530
Date Published: 2021-06-07
QID 375530: F5 BIG-IP ASM WebSocket vulnerability(K18570111)
F5 BIG-IP ASM (Application Security Manager) is a flexible web application firewall that secures web applications in traditional, virtual, and private cloud environments.
CVE-2021-23010: When the BIG-IP ASM system processes WebSocket requests with JSON payloads using the default JSON content profile in the ASM security policy, the BIG-IP ASM bd process may produce a core file.
Vulnerable Component: BIG-IP ASM
Affected Versions:
16.0.0 - 16.0.1
15.1.0 - 15.1.1
14.1.0 - 14.1.3
13.1.0 - 13.1.3
12.1.0 - 12.1.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
When this vulnerability is exploited, the BIG-IP ASM bd process may produce a core file, interrupt traffic processing, and cause a failover event.
Workaround:
To mitigate this vulnerability, you can use the ASM Security menu to create a new custom JSON content profile and then apply it to Allowed WebSocket URLs.
- K18570111 -
support.f5.com/csp/article/K18570111
CVEs related to QID 375530
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K18570111 |
|