QID 379401
Date Published: 2024-02-27
QID 379401: F5 BIG-IP BIG-IP Advanced WAF and BIG-IP Application Security Manager (ASM) Denial of Service (DoS) Vulnerability (K000137416)
CVE-2024-23308: When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause the BD process to terminate. The condition results from setting the Request Body Handling option in the Header-Based Content Profile for an Allowed URL with Apply value and content signatures and detect threat campaigns.
Affected Versions:
F5 BIG-IP (Advanced WAF/ASM) version 17.1.0
QID Detection Logic (Authenticated):
This QID checks for vulnerable version of F5 BIG-IP by running the 'tmsh -q show /sys version' command.
Successful exploitation of this vulnerability allows remote unauthenticated attacker to cause a denial-of-service (DoS) on the BIG-IP system.
Solution
Please check the fixed versions released by the vendor in K000137416
Vendor References
- K000137416 -
my.f5.com/manage/s/article/K000137416
CVEs related to QID 379401
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K000137416 |
|