QID 379389
Date Published: 2024-02-27
QID 379389: F5 BIG-IP Multiple Security Vulnerabilities (K000137522,K000134516)
CVE-2024-22093: When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary.
Affected Versions:
F5 BIG-IP version 17.0.0
F5 BIG-IP version 16.1.0 - 16.1.3
F5 BIG-IP version 15.1.0 - 15.1.8
QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.
Successful exploitation of this vulnerability may allow an authenticated attacker to execute arbitrary Advanced Shell commands.
Solution
Please check the fixed versions released by the vendor in K000137522 and K000134516
Workaround:
Until it is possible to install a fixed version, you can use the following sections as temporary mitigations. These mitigations restrict access to iControl REST to only trusted networks or devices, thereby limiting the attack surface.
Block iControl REST access through the self IP address and Block iControl REST access through the management interface
Workaround:
Until it is possible to install a fixed version, you can use the following sections as temporary mitigations. These mitigations restrict access to iControl REST to only trusted networks or devices, thereby limiting the attack surface.
Block iControl REST access through the self IP address and Block iControl REST access through the management interface
Vendor References
- K000134516 -
my.f5.com/manage/s/article/K000134516 - K000137522 -
my.f5.com/manage/s/article/K000137522
CVEs related to QID 379389
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K000134516 |
|
||
| K000137522 |
|