PT-2023-28195 · F5 · Big-Iq+1

Published

2023-10-10

·

Updated

2023-10-17

·

CVE-2023-41964

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions BIG-IP and BIG-IQ systems (affected versions not specified)
Description The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables. Note that software versions which have reached End of Technical Support (EoTS) are not evaluated.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-41964

Affected Products

Big-Ip
Big-Iq