QID 376690
QID 376690: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) F5 Access for Android vulnerability (K40019131)
F5 BIG-IP ASM (Application Security Manager) is a flexible web application firewall that secures web applications in traditional, virtual, and private cloud environments.
F5 BIG-IP (LTM) Local Traffic Manager is the most popular module offered on F5 Networks BiG-IP platform. The real power of the LTM is it is a Full Proxy, allowing you to augment client and server side connections. All while making informed load balancing decisions on availability, performance, and persistence.
F5 BIG-IP Access Policy Manager (APM) is a secure, flexible, high-performance solution that provides unified global access to your network, cloud, and applications.
An attacker may be able to exploit this vulnerability by tricking a legitimate user running Android version 10 or below into downloading a malicious Android application and executing the malicious application prior to launching the legitimate F5 Access for Android application. The malicious application may then masquerade as the legitimate application in order to steal sensitive information such as usernames and passwords.
Vulnerable Component:
BIG-IP APM,ASM,LTM
Affected Versions:
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
An attacker may be able to exploit this vulnerability by tricking a legitimate user running Android version 10 or below into downloading a malicious Android application and executing the malicious application prior to launching the legitimate F5 Access for Android application. The malicious application may then masquerade as the legitimate application in order to steal sensitive information such as usernames and passwords.
- K40019131 -
support.f5.com/csp/article/K40019131
CVEs related to QID 376690
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K40019131 |
|