QID 379283

Date Published: 2024-02-06

QID 379283: F5 BIG-IP Access Policy Manager (APM) Local Privilege Escalation Vulnerability CVE-2023-43611 (K000136185)

The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. (CVE-2023-43611)
An attacker with an ability to run unprivileged arbitrary code on the target macOS client may be able to abuse an in-progress Edge Client installation to gain local privilege escalation on the client macOS system.

Affected Versions:
F5 BIG-IP version 17.1.0
F5 BIG-IP version 16.1.3.3 - 16.1.4
F5 BIG-IP version 15.1.8 - 15.1.10
F5 BIG-IP version 14.1.5.2 - 14.1.5.6
F5 BIG-IP version 13.1.5.1

QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.

On successful exploitation An attacker with an ability to run unprivileged arbitrary code on the target macOS client may be able to abuse an in-progress Edge Client installation to gain local privilege escalation on the client macOS system.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Currently no fixed version are released by the vendor.

    Vendor References

    CVEs related to QID 379283

    Software Advisories
    Advisory ID Software Component Link