QID 379280
Date Published: 2024-02-06
QID 379280: F5 BIG-IP Access Policy Manager (APM) Clients TunnelCrack Vulnerability (K000136909, K000136907)
BIG-IP APM clients may send IP traffic outside of the VPN tunnel. (CVE-2023-43125)
If a client machine connects to a malicious DNS device, an attacker may be able to trick the client into sending IP traffic outside of the VPN tunnel. Any clear text traffic leaked outside the tunnel may be accessible to the attacker.
Affected Versions:
F5 BIG-IP version 17.1.0
F5 BIG-IP version 16.1.3.3 - 16.1.4
F5 BIG-IP version 15.1.8 - 15.1.10
F5 BIG-IP version 14.1.5.2 - 14.1.5.6
F5 BIG-IP version 13.1.5.1
QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.
If a client machine connects to a malicious DNS device, an attacker may be able to trick the client into sending IP traffic outside of the VPN tunnel. Any clear text traffic leaked outside the tunnel may be accessible to the attacker.
- K000136907 -
my.f5.com/manage/s/article/K000136907 - K000136909 -
my.f5.com/manage/s/article/K000136909
CVEs related to QID 379280
| Advisory ID | Software | Component | Link |
|---|