QID 377991
Date Published: 2023-02-27
QID 377991: F5 BIG-IP Application Security Manager (ASM), Advanced Web Application Firewall (Advanced WAF), and NGINX App Protect Encoded Directory Traversal Security Exposure (K70134152)
The BIG-IP ASM, F5 Advanced Web Application Firewall (Advanced WAF), and NGINX App Protect systems may fail to detect encoded directory traversal in the URL when the affected security policy is enabled with an evasion technique detected violation
Vulnerable Component:
BIG-IP ASM,WAF
Affected Versions:
16.1.0
15.1.0 - 15.1.3
14.1.0 - 14.1.4
13.1.0. - 13.1.4
12.1.0. - 12.1.6
11.6.1. - 11.6.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
An attacker is able to bypass BIG-IP ASM, Advanced WAF, and NGINX App Protect system detection when performing a URL-encoded directory traversal attack.
Solution
For more information about patch details please refer to K81926432
Vendor References
- K70134152 -
support.f5.com/csp/article/K70134152
CVEs related to QID 377991
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K70134152 |
|