QID 376294
QID 376294: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) iControl REST Vulnerability (K11742742)
Undisclosed requests by an authenticated iControl REST user can cause an increase in memory resource utilization.CVE-2022-23023
Vulnerable Component: BIG-IP ASM,LTM,APM
Affected Versions:
16.1.0 - 16.1.2
15.1.0 - 15.1.4
14.1.0 - 14.1.4
13.1.0 - 13.1.4
12.1.0 - 12.1.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
System performance can degrade until the process is either forced to restart or is manually restarted. This vulnerability allows an authenticated remote attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the BIG-IP system.
Solution
The vendor has released patch, for more information please visit: K11742742
Vendor References
- K11742742 -
support.f5.com/csp/article/K11742742
CVEs related to QID 376294
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K11742742 |
|