QID 376577
Date Published: 2022-05-05
QID 376577: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) iControl REST Vulnerability (K23605346)
Undisclosed requests may bypass iControl REST authentication. (CVE-2022-1388)
Vulnerable Component: BIG-IP ASM,LTM,APM
Affected Versions:
16.1.0 - 16.1.2
15.1.0 - 15.1.5
14.1.0 - 14.1.4
13.1.0 - 13.1.4
12.1.0 - 12.1.6
11.6.1 - 11.6.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.
Customers are advised to apply the following mitigations. These mitigations restrict access to iControl REST to only trusted networks or devices, thereby limiting the attack surface.
1. Block iControl REST access through the self IP address
2. Block iControl REST access through the management interface
3. Modify the BIG-IP httpd configuration
- K23605346 -
support.f5.com/csp/article/K23605346
CVEs related to QID 376577
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K23605346 |
|