QID 378745
Date Published: 2023-08-10
QID 378745: F5 BIG-IP Cross-Site Scripting (XSS) Vulnerability (K000134535,K000133474,K000133472)
When an SSL profile is configured on a virtual server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. (CVE-2023-24594).
Vulnerable Component: BIG-IP All Modules
Affected Versions:
Prior to 17.1.0.2
Prior to 16.1.3.5
Prior to 15.1.9.1
Prior to 14.1.5.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
This vulnerability may allows an attacker to run JavaScript in the context of the currently logged-in user.
Solution
The vendor has released patch, for more information please visit: K000134535 K000133474 K000133472Workaround:
CVE-2023-38423 -To mitigate this vulnerability for affected F5 products, you should restrict management access to F5 products to only trusted users and devices over a secure network. For more information about securing access to BIG-IP systems. CVE-2023-38138- To mitigate this vulnerability when finished using the Configuration utility, log off and close all instances of the web browser. CVE-2023-38419- To mitigate this vulnerability blocking iControl SOAP IP addresses will prevent adding new devices to a device trust
CVE-2023-38423 -To mitigate this vulnerability for affected F5 products, you should restrict management access to F5 products to only trusted users and devices over a secure network. For more information about securing access to BIG-IP systems. CVE-2023-38138- To mitigate this vulnerability when finished using the Configuration utility, log off and close all instances of the web browser. CVE-2023-38419- To mitigate this vulnerability blocking iControl SOAP IP addresses will prevent adding new devices to a device trust
Vendor References
- K000133472 -
my.f5.com/manage/s/article/K000133472 - K000133474 -
my.f5.com/manage/s/article/K000133474 - K000134535 -
my.f5.com/manage/s/article/K000134535
CVEs related to QID 378745
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K000133472 |
|
||
| K000133474 |
|
||
| K000134535 |
|