QID 375910
Date Published: 2021-10-04
QID 375910: F5 BIG-IP Access Policy Manager (APM) Guided Configuration Logging Vulnerability (K70652532)
F5 BIG-IP Access Policy Manager (APM) is a secure, flexible, high-performance solution that provides unified global access to your network, cloud, and applications.
When a configuration that contains secure properties is created and deployed from Access Guided Configuration (AGC), secure properties are logged in restnoded logs. (CVE-2021-23046)
Vulnerable Component: BIG-IP APM
Affected Versions:
16.0.0 - 16.0.1
15.1.0 - 15.1.3
14.1.0 - 14.1.4
13.1.0 - 13.1.4
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
Users with access to restnoded logs may gain access to sensitive information from the security properties of F5 Access Guided Configuration.
Solution
The vendor has released patch, for more information please visit: K70652532
Vendor References
- K70652532 -
support.f5.com/csp/article/K70652532
CVEs related to QID 375910
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K70652532 |
|