CVE-2023-28742
published 2023-05-03CVE-2023-28742: When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh. Note: Software versions which have reached End of…
PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.47%
70.9th percentile
When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | >= 13.1.0 < * | * |
| f5 | big-ip | >= 14.1.0 < 14.1.5.4 | 14.1.5.4 |
| f5 | big-ip | >= 15.1.0 < 15.1.8.2 | 15.1.8.2 |
| f5 | big-ip | >= 16.1.0 < 16.1.3.4 | 16.1.3.4 |
| f5 | big-ip | >= 17.0.0 < * | * |
| f5 | big-ip | >= 17.1.0 < 17.1.0.1 | 17.1.0.1 |
| f5 | big-ip_dns | — | — |
| f5 | big-ip_domain_name_system | 13.1.0 – 13.1.5 | — |
| f5 | big-ip_domain_name_system | >= 14.1.0 < 14.1.5.4 | 14.1.5.4 |
| f5 | big-ip_domain_name_system | >= 15.1.0 < 15.1.8.2 | 15.1.8.2 |
| f5 | big-ip_domain_name_system | >= 16.1.0 < 16.1.3.4 | 16.1.3.4 |
| f5 | big-ip_domain_name_system | >= 17.0.0 < 17.1.0.1 | 17.1.0.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gqj6-hjr3-p5gm: When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh
ghsa_unreviewed·2023-05-03
CVE-2023-28742 [HIGH] CWE-78 GHSA-gqj6-hjr3-p5gm: When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh
When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
F5
CVE-2023-28742: When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh
vendor_f5·2023-05-03·CVSS 7.2
CVE-2023-28742 [HIGH] CWE-78 CVE-2023-28742: When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh
CVE-2023-28742: When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh
When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: BIG-IP DNS
Affected Versions: 13.1.0 - 13.1.5; 14.1.0 - 14.1.5.4; 15.1.0 - 15.1.8.2; 16.1.0 - 16.1.3.4; 17.0.0 - 17.1.0.1
F5 Advisory Articles: K000132972
F5 References: https://my.f5.com/manage/s/article/K000132972
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-03
Published