PT-2023-6279 · F5 · Big-Ip Edge Client Installer+18
Published
2023-10-10
·
Updated
2023-10-18
·
CVE-2023-43611
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BIG-IP Edge Client Installer version (affected versions not specified)
BIG-IP Access Policy Manager (affected versions not specified)
BIG-IP Advanced Firewall Manager (affected versions not specified)
BIG-IP Advanced Web Application Firewall (affected versions not specified)
BIG-IP Analytics (affected versions not specified)
BIG-IP Application Acceleration Manager (affected versions not specified)
BIG-IP Application Security Manager (affected versions not specified)
BIG-IP Application Visibility and Reporting (AVR) (affected versions not specified)
BIG-IP Carrier-Grade NAT (CGNAT) (affected versions not specified)
BIG-IP DDoS Hybrid Defender (affected versions not specified)
BIG-IP Domain Name System (affected versions not specified)
BIG-IP Edge Gateway (affected versions not specified)
BIG-IP Fraud Protection Service (affected versions not specified)
BIG-IP Global Traffic Manager (affected versions not specified)
BIG-IP Link Controller (affected versions not specified)
BIG-IP Local Traffic Manager (affected versions not specified)
BIG-IP Policy Enforcement Manager (affected versions not specified)
BIG-IP SSL Orchestrator (affected versions not specified)
BIG-IP WebAccelerator (affected versions not specified)
BIG-IP WebSafe (affected versions not specified)
Description
The issue is related to an incomplete fix for a previous problem, which affects the installation process of the BIG-IP Edge Client Installer on macOS, not following best practices for elevating privileges. Additionally, there is a problem with incorrect verification of cryptographic signatures in various BIG-IP products. This could allow an attacker to elevate their privileges.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Big-Ip Access Policy Manager
Big-Ip Advanced Firewall Manager
Big-Ip Advanced Web Application Firewall
Big-Ip Analytics
Big-Ip Application Acceleration Manager
Big-Ip Application Security Manager
Big-Ip Application Visibility/Reporting
Big-Ip Carrier-Grade Nat
Big-Ip Ddos Hybrid Defender
Big-Ip Domain Name System
Big-Ip Edge Client Installer
Big-Ip Edge Gateway
Big-Ip Fraud Protection Service
Big-Ip Local Traffic Manager
Big-Ip Link Controller
Big-Ip Policy Enforcement Manager
Big-Ip Ssl Orchestrator
Big-Ip Webaccelerator
Big-Ip Websafe