QID 376524
Date Published: 2022-04-08
QID 376524: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) Vim Vulnerability (K08827426)
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. (CVE-2022-0359)
Vulnerable Component: BIG-IP ASM,LTM,APM
Affected Versions:
16.1.0 - 16.1.2
15.1.0 - 15.1.5
14.1.0 - 14.1.4
13.1.0 - 13.1.4
12.1.0 - 12.1.6
11.6.1 - 11.6.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
This vulnerability allows an attacker to input a specially crafted file, leading to arbitrary execution of code or potentially causing services to stop responding.
Solution
For more information about patch details please refer to K08827426
Vendor References
- K08827426 -
support.f5.com/csp/article/K08827426
CVEs related to QID 376524
Software Advisories
| Advisory ID | Software | Component | Link |
|---|