QID 376697
Date Published: 2022-06-27
QID 376697: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) iControl REST Vulnerability (K15101402)
F5 BIG-IP ASM (Application Security Manager) is a flexible web application firewall that secures web applications in traditional, virtual, and private cloud environments.
F5 BIG-IP (LTM) Local Traffic Manager is the most popular module offered on F5 Networks BiG-IP platform. The real power of the LTM is it is a Full Proxy, allowing you to augment client and server side connections. All while making informed load balancing decisions on availability, performance, and persistence.
F5 BIG-IP Access Policy Manager (APM) is a secure, flexible, high-performance solution that provides unified global access to your network, cloud, and applications.
An authenticated iControl REST user with at least guest role privileges can cause processing delays to iControl REST requests via undisclosed requests. (CVE-2022-1468)
Vulnerable Component:
BIG-IP APM,ASM,LTM
Affected Versions:
16.1.0 - 16.1.2
15.1.0 - 15.1.5
14.1.0 - 14.1.4
13.1.0 - 13.1.5
12.1.0 - 12.1.6
11.6.1 - 11.6.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
Processing delays to iControl REST requests can occur until the iControl REST daemon is either forced to restart or manually restarted. This vulnerability allows a remote authenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the iControl REST daemon. There is no data plane exposure; this is a control plane issue only.
- K15101402 -
support.f5.com/csp/article/K15101402
CVEs related to QID 376697
| Advisory ID | Software | Component | Link |
|---|