QID 376601
Date Published: 2022-05-17
QID 376601: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) TMUI Cross-Site Request Forgery (CSRF) Vulnerability (K49905324)
A cross-site request forgery (CSRF) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. This vulnerability allows an attacker to run a limited set of commands: ping, traceroute, and WOM diagnostics. (CVE-2022-1389)
Affected Versions:
16.1.0 - 16.1.2
15.1.0 - 15.1.5
14.1.0 - 14.1.4
13.1.0 - 13.1.5
12.1.0 - 12.1.6
11.6.1 - 11.6.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
An attacker may exploit this vulnerability by causing an authenticated user to send a crafted request to the BIG-IP Configuration utility. If successful, an attacker can run a limited set of ping, traceroute, and WOM diagnostics commands. This is a control plane issue; there is no data plane exposure.
- K49905324 -
support.f5.com/csp/article/K49905324
CVEs related to QID 376601
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K49905324 |
|