QID 376747

Date Published: 2022-07-27

QID 376747: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) Intel processors MMIO stale data Vulnerability (K08152433)

Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.CVE-2022-21166

Vulnerable Component: BIG-IP ASM,LTM,APM

Affected Versions:
17.0.0
16.1.0 - 16.1.3
15.1.0 - 15.1.6
14.1.0 - 14.1.5
13.1.0 - 13.1.5

QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.

Successful exploitation of this vulnerability can lead to disclosure of sensitive information.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    For more information about patch details please refer to K08152433
    Vendor References

    CVEs related to QID 376747

    Software Advisories
    Advisory ID Software Component Link
    K08152433 URL Logo support.f5.com/csp/article/K08152433