QID 378787

Date Published: 2023-08-23

QID 378787: F5 BIG-IP Denial of Service (DoS) Vulnerability (K000135831)

c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the connection. This issue has been patched in version 1.19.1.

Vulnerable Component: BIG-IP All Modules

Affected Versions:
17.1.0
16.1.0 - 16.1.3
15.1.0 - 15.1.9
14.1.0 - 14.1.5
13.1.0 - 13.1.5

QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.

This vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or cause a denial-of-service (DoS).

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released patch, for more information please visit: K000135831
    Vendor References

    CVEs related to QID 378787

    Software Advisories
    Advisory ID Software Component Link
    K000135831 URL Logo my.f5.com/manage/s/article/K000135831