QID 376793
Date Published: 2022-08-10
QID 376793: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) Big-ip Irules Vulnerability cve-2022-33962 (K80970653)
Certain iRules commands may allow an attacker to bypass the access control restrictions for a self IP address, regardless of the port lockdown settings.CVE-2022-33962
Vulnerable Component: BIG-IP ASM,LTM,APM
Affected Versions:
17.0.0
16.1.0 - 16.1.3
15.1.0 - 15.1.6
14.1.0 - 14.1.5
13.1.0 - 13.1.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
This vulnerability may allow an attacker to connect to internal IP addresses/services through an iRule that allows unconstrained manipulation of the target of the pool or node commands.
Solution
For more information about patch details please refer to K80970653
Vendor References
- K80970653 -
support.f5.com/csp/article/K80970653
CVEs related to QID 376793
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K80970653 |
|