QID 378010
Date Published: 2023-03-08
QID 378010: F5 BIG-IP Application Security Manager (ASM) and Advanced WAF Attack Signature Check Failure on Certain Hypertext Transfer Protocol (HTTP) Requests (K53593534)
The BIG-IP ASM and F5 Advanced Web Application Firewall (Advanced WAF) attack signature check may fail to detect and block certain HTTP requests.
Vulnerable Component:
BIG-IP ASM,WAF
Affected Versions:
16.1.0 - 16.1.2
15.1.0 - 15.1.5
14.1.0 - 14.1.4
13.1.0 - 13.1.4
12.1.0 - 12.1.6
11.6.1 - 11.6.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
The attack signature check fails to detect and block such requests, as expected of a security policy.
Solution
Please refer to K53593534 for more information.
Vendor References
- K53593534 -
my.f5.com/manage/s/article/K53593534
CVEs related to QID 378010
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K53593534 |
|