QID 378003
Date Published: 2023-02-23
QID 378003: F5 BIG-IP ASM and Advanced WAF Attack Signature Check Failure Security Exposure (K80945213)
A BIG-IP ASM and F5 Advanced Web Application Firewall (Advanced WAF) attack signature check may fail to detect and block certain GET requests when cross-site request forgery (CSRF) protection is enabled.
Vulnerable Component:
BIG-IP ASM,WAF
Affected Versions:
15.1.0 - 15.1.4
14.1.0 - 14.1.4
13.1.0. - 13.1.4
12.1.0. - 12.1.6
11.6.1. - 11.6.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
Attackers may be able to bypass BIG-IP ASM and Advanced WAF attack signature matching on GET requests.
Solution
For more information about patch details please refer to K80945213
Vendor References
- K80945213 -
support.f5.com/csp/article/K80945213
CVEs related to QID 378003
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K80945213 |
|