CVE-2023-38419
published 2023-08-02CVE-2023-38419: An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software…
PriorityP421medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
0.45%
36.6th percentile
An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
124 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | >= 13.1.0 < * | * |
| f5 | big-ip | >= 14.1.0 < 14.1.5.5 | 14.1.5.5 |
| f5 | big-ip | >= 15.1.0 < 15.1.9.1 | 15.1.9.1 |
| f5 | big-ip | >= 16.1.0 < 16.1.3.5 | 16.1.3.5 |
| f5 | big-ip | >= 17.1.0 < 17.1.0.2 | 17.1.0.2 |
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | 13.1.0 – 13.1.5 | — |
| f5 | big-ip_access_policy_manager | >= 14.1.0 < 14.1.5.5 | 14.1.5.5 |
| f5 | big-ip_access_policy_manager | >= 15.1.0 < 15.1.9.1 | 15.1.9.1 |
| f5 | big-ip_access_policy_manager | >= 16.1.0 < 16.1.3.5 | 16.1.3.5 |
| f5 | big-ip_access_policy_manager | >= 17.0.0 < 17.1.0.2 | 17.1.0.2 |
| f5 | big-ip_advanced_firewall_manager | 13.1.0 – 13.1.5 | — |
| f5 | big-ip_advanced_firewall_manager | >= 14.1.0 < 14.1.5.5 | 14.1.5.5 |
| f5 | big-ip_advanced_firewall_manager | >= 15.1.0 < 15.1.9.1 | 15.1.9.1 |
| f5 | big-ip_advanced_firewall_manager | >= 16.1.0 < 16.1.3.5 | 16.1.3.5 |
| f5 | big-ip_advanced_firewall_manager | >= 17.0.0 < 17.1.0.2 | 17.1.0.2 |
| f5 | big-ip_advanced_waf | — | — |
| f5 | big-ip_advanced_web_application_firewall | 13.1.0 – 13.1.5 | — |
| f5 | big-ip_advanced_web_application_firewall | >= 14.1.0 < 14.1.5.5 | 14.1.5.5 |
| f5 | big-ip_advanced_web_application_firewall | >= 15.1.0 < 15.1.9.1 | 15.1.9.1 |
| f5 | big-ip_advanced_web_application_firewall | >= 16.1.0 < 16.1.3.5 | 16.1.3.5 |
| f5 | big-ip_advanced_web_application_firewall | >= 17.0.0 < 17.1.0.2 | 17.1.0.2 |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 13.1.0 – 13.1.5 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x3f8-jwjc-w444: An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests
ghsa_unreviewed·2023-08-02
CVE-2023-38419 [MEDIUM] CWE-755 GHSA-x3f8-jwjc-w444: An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests
An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
F5
CVE-2023-38419: An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending...
vendor_f5·2023-08-02·CVSS 4.3
CVE-2023-38419 [MEDIUM] CWE-755 CVE-2023-38419: An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending...
CVE-2023-38419: An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending...
An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP AVR, BIG-IP Advanced WAF, BIG-IP Analytics, BIG-IP CGNAT, BIG-IP DHD, BIG-IP DNS, BIG-IP Edge Gateway, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP SSLO, BIG-IP WebAccelerator, BIG-IP WebSafe, BIG-IQ, iControl SOAP
Affected Versions: 13.1.0 - 13.1.5; 14.1.0 - 14.1.5.5; 15.1.0 - 15.1.9.1; 16.1.0 - 16.1.3.5; 17.0.0 - 17
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-08-02
Published