QID 376775

Date Published: 2022-08-18

QID 376775: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) Retbleed cpu vulnerability cve-2022-29901 (K83713003)

Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.K57185580: RetBleed CPU vulnerability CVE-2022-29900

Vulnerable Component: BIG-IP ASM,LTM,APM

Affected Versions:
15.1.4 - 15.1.6
14.1.4.1 - 14.1.5

QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.

A local authenticated attacker can exploit the Intel vulnerability to allow information disclosure. Only the VELOS BX110 platform is vulnerable.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    For more information about patch details please refer to K83713003
    Vendor References

    CVEs related to QID 376775

    Software Advisories
    Advisory ID Software Component Link
    K83713003 URL Logo support.f5.com/csp/article/K83713003