QID 378095
Date Published: 2023-03-22
QID 378095: F5 BIG-IP Access Policy Manager (APM) BIG-IP Edge Client for Windows Vulnerability CVE-2023-22283 (K07143733)
A DLL hijacking vulnerability exists in the BIG-IP Edge Client for Windows. User interaction and administrative privileges are required to exploit this vulnerability because the victim user needs to run the executable on the system and the attacker requires administrative privileges for modifying the files in the trusted search path. (CVE-2023-22283).
Vulnerable Component: BIG-IP APM
Affected Versions:
17.0.0
16.1.0 - 16.1.3
15.1.0 - 15.1.8
14.1.0 - 14.1.5
13.1.0 - 13.1.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
This vulnerability may allow an attacker with administrative access to the client system to execute arbitrary system commands when the user runs the BIG-IP Edge Client for Windows
- K07143733 -
my.f5.com/manage/s/article/K07143733
CVEs related to QID 378095
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K07143733 |
|