QID 379395
Date Published: 2024-02-22
QID 379395: F5 BIG-IP ADVANCED WAF and Application Security Manager (ASM) WebSocket Denial of Service (DoS) Vulnerability (K000135873)
CVE-2024-21849: When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) process to terminate.
Affected Versions:
F5 BIG-IP (Advanced WAF/ASM) version 16.1.0 - 16.1.3
QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.
Successful exploitation of this vulnerability may allow a remote unauthenticated attacker to cause a denial-of-service (DoS) on the BIG-IP system.
Solution
Please check the fixed versions released by the vendor in K000135873
Vendor References
- K000135873 -
my.f5.com/manage/s/article/K000135873
CVEs related to QID 379395
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K000135873 |
|