QID 377876
Date Published: 2023-02-27
QID 377876: F5 BIG-IP Advanced WAF and Application Security Manager (ASM) WebSocket Security Exposure (K94142349)
Some WebSockets security vulnerabilities arise when an attacker makes a cross-domain WebSocket connection from a web site that the attacker controls.
Vulnerable Component:
BIG-IP AFM,WAF
Affected Versions:
16.1.0 - 16.1.2
15.1.0 - 15.1.5
14.1.0 - 14.1.4
13.1.0. - 13.1.4
12.1.0. - 12.1.6
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
The attack signature check fails to detect and block requests, as expected of a security policy.
Solution
For more information about patch details please refer to: K25451853
Vendor References
- K94142349 -
support.f5.com/csp/article/K94142349
CVEs related to QID 377876
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K94142349 |
|