QID 379294
Date Published: 2024-02-06
QID 379294: F5 BIG-IP Configuration Utility Directory Traversal Vulnerability (K000132768)
CVE-2023-28406 - A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that may allow an authenticated attacker to read files with an .xml extension. Access to restricted information is limited and the attacker does not control what information is obtained.
Affected Versions:
F5 BIG-IP version 17.0.0
F5 BIG-IP version 16.1.0 - 16.1.3
F5 BIG-IP version 15.1.0 - 15.1.8
F5 BIG-IP version 14.1.0 - 14.1.5
F5 BIG-IP version 13.1.0 - 13.1.5
QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.
If a client machine connects to a malicious DNS device, an attacker may be able to trick the client into sending IP traffic outside of the VPN tunnel. Any clear text traffic leaked outside the tunnel may be accessible to the attacker.
Workaround:
The vendor advised the following two workarounds as temporary fixes:
Block Configuration utility access through self IP addresses
Block Configuration utility access through the management interface
- K000132768 -
my.f5.com/manage/s/article/K000132768
CVEs related to QID 379294
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K000132768 |
|