CVE-2023-22374
A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 72.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appliance mode BIG-IP, a successful exploit of this vulnerability can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVSS 3.1
- 8.5 HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 72.65% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-134
- Affected
- f5/big-ip access policy manager · f5/big-ip advanced firewall manager · f5/big-ip analytics · f5/big-ip application acceleration manager · f5/big-ip application security manager · f5/big-ip ddos hybrid defender · f5/big-ip domain name system · f5/big-ip fraud protection service · f5/big-ip link controller · f5/big-ip local traffic manager · f5/big-ip policy enforcement manager · f5/big-ip ssl orchestrator
- Source
- f5sirt@f5.com
References
- https://my.f5.com/manage/s/article/K000130415Vendor Advisory
- https://my.f5.com/manage/s/article/K000130415Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.