QID 379308

Date Published: 2024-02-22

QID 379308: F5 BIG-IP Audit Log Vulnerability (K06110200)

CVE-2023-43485 - An authenticated attacker with at least auditor role privileges can view shared secret. There is no data plane exposure; this is a control plane issue only
Affected Versions:
F5 BIG-IP version 16.1.0 - 16.1.3
F5 BIG-IP version 15.1.0 - 15.1.8
F5 BIG-IP version 14.1.0 - 14.1.5
F5 BIG-IP version 13.1.0 - 13.1.5

QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.

An authenticated attacker with at least auditor role privileges can view shared secret. There is no data plane exposure; this is a control plane issue only

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Please check the fixed versions released by the vendor in K06110200
    Vendor References

    CVEs related to QID 379308

    Software Advisories
    Advisory ID Software Component Link
    K06110200 URL Logo my.f5.com/manage/s/article/K06110200