QID 376792
Date Published: 2022-08-10
QID 376792: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) Big-ip Local Traffic Manager (LTM) and Access Policy Manager (APM) ntlm Vulnerability cve-2022-33968 (K23465404)
When an LTM monitor or APM SSO is configured on a virtual server, and NTLM challenge-response is in use, undisclosed traffic can cause a buffer over-read.CVE-2022-33968
Vulnerable Component: BIG-IP ASM,LTM,APM
Affected Versions:
17.0.0
16.1.0 - 16.1.3
15.1.0 - 15.1.6
14.1.0 - 14.1.5
13.1.0 - 13.1.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
If an attacker controls the server that handles monitor traffic or the APM SSO endpoint, arbitrary system memory may be leaked to the server. There is no control plane exposure; this is a data plane issue only. To exploit this vulnerability, an attacker must have a privileged network position.
Solution
For more information about patch details please refer to K23465404
Vendor References
- K23465404 -
support.f5.com/csp/article/K23465404
CVEs related to QID 376792
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K23465404 |
|