F5 Products Multiple Vulnerabilities
RISK: High Risk
TYPE: Operating Systems - Networks OS
Multiple vulnerabilities were identified in F5 Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, information disclosure and data manipulation on the targeted system.
Note:
No patch is currently available for CVE-2022-40304 of the affected products.
No patch and workaround is currently available for CVE-2023-29469 of the affected products.
Impact
- Denial of Service
- Information Disclosure
- Data Manipulation
System / Technologies affected
BIG-IP (AFM, Analytics, AAM, DNS, FPS, Link Controller, LTM, PEM, Advanced WAF, ASM)
- 15.1.0 - 15.1.10
- 16.1.0 - 16.1.4
- 17.1.0 - 17.1.1
BIG-IQ Centralized Management
- 8.1.0 - 8.3.0
Traffix SDC
- 5.1.0
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
Apply workarounds issued by the vendor:
Workaround:
Reduce the vulnerability of attacks of CVE-2022-40304 by following workaround:
Do not allow Document Type Definition (DTD) validation in XML profiles or permit DTD validation in monitors or iRules that contain custom XML.
Vulnerability Identifier
Source
Related Link
Share with