QID 377959
Date Published: 2023-02-07
QID 377959: F5 BIG-IP IControl SOAP Vulnerability CVE-2023-22374 (K35253541)
BIG-IP has released a security update for BIG-IP to fix the vulnerabilities.
Vulnerable Component:
Affected Versions:
17.0.0
16.1.0 - 16.1.3
15.1.0 - 15.1.8
14.1.0 - 14.1.5
13.1.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
This vulnerability may allow an authenticated attacker with network access to iControl SOAP through the BIG-IP management port and/or self IP addresses to cause a denial-of-service (DoS) on the iControl SOAP CGI process or potentially execute arbitrary system commands
Solution
Please refer to K000130415 for more information. Workaround:
If you follow best practices in securing access to the management interface and self IP addresses of BIG-IP systems, you help to minimize the attack surface. Impact of procedure: Blocking iControl SOAP IP addresses will prevent adding new devices to a device trust. Log in to the TMOS Shell (tmsh) by entering the following command: tmsh Remove all IP addresses or ranges of IP addresses from the list of allowed addresses by entering the following command: modify /sys icontrol-soap allow replace-all-with { } Save the change by entering the following command: save /sys config For more information about limiting access to trusted users, refer to K17459: Restricting access to the iControl SOAP API by source IP address.
If you follow best practices in securing access to the management interface and self IP addresses of BIG-IP systems, you help to minimize the attack surface. Impact of procedure: Blocking iControl SOAP IP addresses will prevent adding new devices to a device trust. Log in to the TMOS Shell (tmsh) by entering the following command: tmsh Remove all IP addresses or ranges of IP addresses from the list of allowed addresses by entering the following command: modify /sys icontrol-soap allow replace-all-with { } Save the change by entering the following command: save /sys config For more information about limiting access to trusted users, refer to K17459: Restricting access to the iControl SOAP API by source IP address.
Vendor References
- K000130415 -
my.f5.com/manage/s/article/K000130415
CVEs related to QID 377959
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K000130415 |
|