PT-2023-6394 · F5 · Big-Ip Domain Name System+5
Published
2023-10-10
·
Updated
2023-11-02
·
CVE-2023-43746
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP versions prior to the fixed version
Description
The issue is related to insecure privilege management in BIG-IP Access Policy Manager, BIG-IP Advanced Firewall Manager, BIG-IP Application Security Manager, BIG-IP Domain Name System, and BIG-IP Local Traffic Manager. An authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing BIG-IP external monitor on a BIG-IP system. A successful exploit can allow the attacker to cross a security boundary, potentially impacting the confidentiality and integrity of protected information.
Recommendations
For versions prior to the fixed version, consider disabling the Administrator role or restricting access to the BIG-IP external monitor as a temporary workaround until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Big-Ip
Big-Ip Access Policy Manager
Big-Ip Advanced Firewall Manager
Big-Ip Application Security Manager
Big-Ip Domain Name System
Big-Ip Local Traffic Manager