QID 379280

Date Published: 2024-02-06

QID 379280: F5 BIG-IP Access Policy Manager (APM) Clients TunnelCrack Vulnerability (K000136909, K000136907)

BIG-IP APM clients may send IP traffic outside of the VPN tunnel. (CVE-2023-43125)
If a client machine connects to a malicious DNS device, an attacker may be able to trick the client into sending IP traffic outside of the VPN tunnel. Any clear text traffic leaked outside the tunnel may be accessible to the attacker.

Affected Versions:
F5 BIG-IP version 17.1.0
F5 BIG-IP version 16.1.3.3 - 16.1.4
F5 BIG-IP version 15.1.8 - 15.1.10
F5 BIG-IP version 14.1.5.2 - 14.1.5.6
F5 BIG-IP version 13.1.5.1

QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.

If a client machine connects to a malicious DNS device, an attacker may be able to trick the client into sending IP traffic outside of the VPN tunnel. Any clear text traffic leaked outside the tunnel may be accessible to the attacker.

  • CVSS V3 rated as Critical - 8.2 severity.
  • CVSS V2 rated as Critical - 8.5 severity.
  • Solution
    Currently no fixed version are released by the vendor.

    CVEs related to QID 379280

    Software Advisories
    Advisory ID Software Component Link