PT-2023-6279 · F5 · Big-Ip Local Traffic Manager +18

Published

2023-10-10

·

Updated

2023-10-18

·

CVE-2023-43611

CVSS v3.1
7.8
VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

BIG-IP Edge Client Installer version (affected versions not specified)

BIG-IP Access Policy Manager (affected versions not specified)

BIG-IP Advanced Firewall Manager (affected versions not specified)

BIG-IP Advanced Web Application Firewall (affected versions not specified)

BIG-IP Analytics (affected versions not specified)

BIG-IP Application Acceleration Manager (affected versions not specified)

BIG-IP Application Security Manager (affected versions not specified)

BIG-IP Application Visibility and Reporting (AVR) (affected versions not specified)

BIG-IP Carrier-Grade NAT (CGNAT) (affected versions not specified)

BIG-IP DDoS Hybrid Defender (affected versions not specified)

BIG-IP Domain Name System (affected versions not specified)

BIG-IP Edge Gateway (affected versions not specified)

BIG-IP Fraud Protection Service (affected versions not specified)

BIG-IP Global Traffic Manager (affected versions not specified)

BIG-IP Link Controller (affected versions not specified)

BIG-IP Local Traffic Manager (affected versions not specified)

BIG-IP Policy Enforcement Manager (affected versions not specified)

BIG-IP SSL Orchestrator (affected versions not specified)

BIG-IP WebAccelerator (affected versions not specified)

BIG-IP WebSafe (affected versions not specified)

Description:

The issue is related to an incomplete fix for a previous problem, which affects the installation process of the BIG-IP Edge Client Installer on macOS, not following best practices for elevating privileges. Additionally, there is a problem with incorrect verification of cryptographic signatures in various BIG-IP products. This could allow an attacker to elevate their privileges.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

BDU:2023-06989
CVE-2023-43611

Affected Products

Big-Ip Access Policy Manager
Big-Ip Advanced Firewall Manager
Big-Ip Advanced Web Application Firewall
Big-Ip Analytics
Big-Ip Application Acceleration Manager
Big-Ip Application Security Manager
Big-Ip Application Visibility/Reporting
Big-Ip Carrier-Grade Nat
Big-Ip Ddos Hybrid Defender
Big-Ip Domain Name System
Big-Ip Edge Client Installer
Big-Ip Edge Gateway
Big-Ip Fraud Protection Service
Big-Ip Local Traffic Manager
Big-Ip Link Controller
Big-Ip Policy Enforcement Manager
Big-Ip Ssl Orchestrator
Big-Ip Webaccelerator
Big-Ip Websafe