QID 377992
Date Published: 2023-02-27
QID 377992: F5 BIG-IP Application Security Manager (ASM) , Advanced WAF, and NGINX App Protect Normalizing Security Exposure (K67397230) .
The BIG-IP Application Security Manager (ASM) , F5 Advanced Web Application Firewall (Advanced WAF), and NGINX App Protect systems incorrectly normalize undisclosed strings
Vulnerable Component:
BIG-IP ASM,WAF
Affected Versions:
16.1.0 - 16.1.2
15.1.0 - 15.1.4
14.1.0 - 14.1.4
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
The attack signature check fails to detect and block such requests, as expected of a security policy.
Solution
For more information about patch details please refer to K67397230
Vendor References
- K67397230 -
support.f5.com/csp/article/K67397230
CVEs related to QID 377992
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K67397230 |
|