QID 379308
Date Published: 2024-02-22
QID 379308: F5 BIG-IP Audit Log Vulnerability (K06110200)
CVE-2023-43485 - An authenticated attacker with at least auditor role privileges can view shared secret. There is no data plane exposure; this is a control plane issue only
Affected Versions:
F5 BIG-IP version 16.1.0 - 16.1.3
F5 BIG-IP version 15.1.0 - 15.1.8
F5 BIG-IP version 14.1.0 - 14.1.5
F5 BIG-IP version 13.1.0 - 13.1.5
QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.
An authenticated attacker with at least auditor role privileges can view shared secret. There is no data plane exposure; this is a control plane issue only
Solution
Please check the fixed versions released by the vendor in K06110200
Vendor References
- K06110200 -
my.f5.com/manage/s/article/K06110200
CVEs related to QID 379308
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K06110200 |
|