QID 379398
Date Published: 2024-02-22
QID 379398: F5 BIG-IP BIG-IP Advanced WAF and BIG-IP Application Security Manager (ASM) Denial of Service (DoS) Vulnerability (K000137270)
CVE-2024-21789: When a BIG-IP Advanced WAF/ASM security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.
Affected Versions:
F5 BIG-IP (Advanced WAF/ASM) version17.1.0
QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.
Successful exploitation of this vulnerability allows a remote unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the BIG-IP system.
Solution
Please check the fixed versions released by the vendor in K000137270
Vendor References
- K000137270 -
my.f5.com/manage/s/article/K000137270
CVEs related to QID 379398
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K000137270 |
|