QID 378099
Date Published: 2023-03-22
QID 378099: F5 BIG-IP iControl REST and tmsh Vulnerability CVE-2023-22326(K83284425)
Incorrect permission assignment vulnerabilities exist in the iControl REST and TMOS shell (tmsh) dig command which may allow an authenticated attacker with resource administrator or administrator role privileges to view sensitive information. (CVE-2023-22326).
Vulnerable Component: BIG-IP All Modules
Affected Versions:
17.0.0
16.1.0 - 16.1.3
15.1.0 - 15.1.8
14.1.0 - 14.1.5
13.1.0 - 13.1.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
An authenticated attacker with resource administrator or administrator role privileges may exploit these vulnerabilities by sending a crafted request remotely through iControl REST and locally through a crafted tmsh command. If the exploit is successful, an attacker can view sensitive information. There is no data plane exposure; this is a control plane issue only.
- K83284425 -
my.f5.com/manage/s/article/K83284425
CVEs related to QID 378099
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K83284425 |
|