QID 379283
Date Published: 2024-02-06
QID 379283: F5 BIG-IP Access Policy Manager (APM) Local Privilege Escalation Vulnerability CVE-2023-43611 (K000136185)
The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. (CVE-2023-43611)
An attacker with an ability to run unprivileged arbitrary code on the target macOS client may be able to abuse an in-progress Edge Client installation to gain local privilege escalation on the client macOS system.
Affected Versions:
F5 BIG-IP version 17.1.0
F5 BIG-IP version 16.1.3.3 - 16.1.4
F5 BIG-IP version 15.1.8 - 15.1.10
F5 BIG-IP version 14.1.5.2 - 14.1.5.6
F5 BIG-IP version 13.1.5.1
QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.
On successful exploitation An attacker with an ability to run unprivileged arbitrary code on the target macOS client may be able to abuse an in-progress Edge Client installation to gain local privilege escalation on the client macOS system.
- K000136185 -
my.f5.com/manage/s/article/K000136185
CVEs related to QID 379283
| Advisory ID | Software | Component | Link |
|---|