QID 376466
Date Published: 2022-03-14
QID 376466: F5 BIG-IP Application Security Manager (ASM) Attack Signature Bypass Vulnerability (K41503304)
The F5 Advanced Web Application Firewall (Advanced WAF), BIG-IP ASM, and NGINX App Protect systems attack signature check may fail to match attack signature 200000128, as expected, for certain undisclosed requests.
This issue occurs when all of the following conditions are met:
Advanced WAF, BIG-IP ASM modules, or NGINX App Protect is configured.
Attack signature 200000128 is enabled on the policy.
Vulnerable Component: BIG-IP ASM
Affected Versions:
16.1.0
16.0.0 - 16.0.1
15.1.0 - 15.1.3
14.1.0 - 14.1.4
13.1.0 - 13.1.4>BR>
12.1.0 - 12.1.6
11.6.1 - 11.6.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
The attack signature 200000128 check fails to detect and block such requests.
- K41503304 -
support.f5.com/csp/article/K41503304
CVEs related to QID 376466
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K41503304 |
|