QID 376751

Date Published: 2022-07-27

QID 376751: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) Intel BIOS Vulnerability (K55051330)

Improper access control in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. (CVE-2021-33123

Vulnerable Component: BIG-IP ASM,LTM,APM

Affected Versions:
17.0.0
16.1.0 - 16.1.3
15.1.0 - 15.1.6
14.1.0 - 14.1.5
13.1.0 - 13.1.5

QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.

A local attacker logged in as a privileged user can exploit the vulnerability to potentially enable escalation of privileges.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    For more information about patch details please refer to K55051330
    Vendor References

    CVEs related to QID 376751

    Software Advisories
    Advisory ID Software Component Link
    K55051330 URL Logo support.f5.com/csp/article/K55051330