QID 378745

Date Published: 2023-08-10

QID 378745: F5 BIG-IP Cross-Site Scripting (XSS) Vulnerability (K000134535,K000133474,K000133472)

When an SSL profile is configured on a virtual server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. (CVE-2023-24594).

Vulnerable Component: BIG-IP All Modules

Affected Versions:
Prior to 17.1.0.2
Prior to 16.1.3.5
Prior to 15.1.9.1
Prior to 14.1.5.5

QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.

This vulnerability may allows an attacker to run JavaScript in the context of the currently logged-in user.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released patch, for more information please visit: K000134535 K000133474 K000133472Workaround:
    CVE-2023-38423 -To mitigate this vulnerability for affected F5 products, you should restrict management access to F5 products to only trusted users and devices over a secure network. For more information about securing access to BIG-IP systems. CVE-2023-38138- To mitigate this vulnerability when finished using the Configuration utility, log off and close all instances of the web browser. CVE-2023-38419- To mitigate this vulnerability blocking iControl SOAP IP addresses will prevent adding new devices to a device trust

    CVEs related to QID 378745

    Software Advisories
    Advisory ID Software Component Link
    K000133472 URL Logo my.f5.com/manage/s/article/K000133472
    K000133474 URL Logo my.f5.com/manage/s/article/K000133474
    K000134535 URL Logo my.f5.com/manage/s/article/K000134535