QID 379311

Date Published: 2024-02-06

QID 379311: F5 BIG-IP Sensitive Information Disclosure Vulnerability (K20850144, K20307245)

The BIG-IP and BIG-IQ systems do not encrypt the values of two Database (DB) variables, a password used for a proxy server connection and a RADIUS/TACACS+ shared secret. (CVE-2023-41964) Affected Versions:
F5 BIG-IP version 16.1.0 - 16.1.3
F5 BIG-IP version 15.1.0 - 15.1.8
F5 BIG-IP version 14.1.0 - 14.1.5
F5 BIG-IP version 13.1.0 - 13.1.5

QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.

On Successful exploitation of this vulnerability, an authenticated attacker may be able to gain access to privileged information by way of the DB variables.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Thge vendor has released fixes pertaining this vulnerability in K20850144 and K20307245
    Workaround:
    The vendor has advised the following workarounds: Block SSH access through self IP addresses
    Block SSH access through the management interface

    CVEs related to QID 379311

    Software Advisories
    Advisory ID Software Component Link
    K20307245 URL Logo my.f5.com/manage/s/article/K20307245
    K20850144 URL Logo my.f5.com/manage/s/article/K20850144