QID 379377
Date Published: 2024-02-29
QID 379377: F5 BIG-IP Multiple Security Vulnerabilities (K32544615,K000137675,K91054692)
CVE-2024-22389 - This vulnerability may allow an authenticated attacker to use deleted or updated API tokens on the peer device until they expire.
CVE-2024-23314 - A remote unauthenticated attacker to cause a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure.
CVE-2024-23976 - An authenticated attacker with local system access and the Administrator role may be able to bypass Appliance mode restrictions.
Affected Versions:
F5 BIG-IP version 17.1.0
F5 BIG-IP version 16.1.0 - 16.1.3
F5 BIG-IP version 15.1.0 - 15.1.8
QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.
This vulnerability may allow an authenticated attacker to use deleted or updated API tokens on the peer device until they expire, a remote unauthenticated attacker to cause a denial-of-service (DoS) on the BIG-IP system. , An authenticated attacker with local system access and the Administrator role may be able to bypass Appliance mode restrictions
- K000137675 -
my.f5.com/manage/s/article/K000137675 - K32544615 -
my.f5.com/manage/s/article/K32544615 - K91054692 -
my.f5.com/manage/s/article/K91054692
CVEs related to QID 379377
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K000137675 |
|
||
| K32544615 |
|
||
| K91054692 |
|