QID 379120

Date Published: 2024-01-02

QID 379120: F5 BIG-IP Hypertext Transfer Protocol (HTTP) Request/Response Smuggling Vulnerability (K000137322)

A specifically crafted HTTP request may lead the BIG-IP system to generate multiple HTTP redirect responses.

This issue occurs when all of the following conditions are met:
A virtual server has one or more of the following configurations:
An iRule with an HTTP::redirect or an HTTP::respond command that redirects HTP requests based on the content of the request.
An LTM policy that redirects HTTP requests based on the content of the request.
The virtual server receives and processes a malformed HTTP request.

Affected Versions:
F5 BIG-IP version 17.1.0 - 17.1.1
F5 BIG-IP version 16.1.0 - 16.1.4
F5 BIG-IP version 15.1.0 - 15.1.10
F5 BIG-IP version 14.1.0 - 14.1.5
F5 BIG-IP version 13.1.0 - 13.1.5

QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.

On Successful exploitation the BIG-IP system may respond with multiple HTTP redirect responses. Intermediate systems may cache these HTTP redirect responses and clients may unexpectedly receive them.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Currently no fixed version are released by the vendor.

    Workaround:
    To work around this issue, you can associate the following mitigation iRule to the affected BIG-IP virtual server. The mitigation iRule should be listed as the first iRule on the virtual servers iRule list before the HTTP redirection iRules: If an LTM policy is redirecting HTTP requests, convert the LTM policy redirect conditions to an iRule with HTTP::redirect syntax.
    For more information please check K000137322

    Vendor References

    CVEs related to QID 379120

    Software Advisories
    Advisory ID Software Component Link

    © CVE.report 2026

    Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

    CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

    Free CVE JSON API cve.report/api

    CVE.report and Source URL Uptime Status status.cve.report