CVE-2023-43746Privilege Defined With Unsafe Actions in F5 Big-ip Application Security Manager

Severity
8.7HIGHNVD
EPSS
0.1%
top 82.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 10

Description

When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing BIG-IP external monitor on a BIG-IP system. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:NExploitability: 2.3 | Impact: 5.8

Affected Packages19 packages

NVDf5/big-ip_domain_name_system15.1.015.1.9+2
CVEListV5f5/big-ip16.1.016.1.4+3
NVDf5/big-ip_websafe15.1.015.1.9+2
NVDf5/big-ip_analytics15.1.015.1.9+2

🔴Vulnerability Details

2
GHSA
GHSA-r7qm-xv29-cxj4: When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing BIG2023-10-10
CVEList
BIG-IP Appliance mode external monitor vulnerability2023-10-10

📋Vendor Advisories

1
F5
CVE-2023-43746: When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance...2023-10-10
CVE-2023-43746 — Privilege Defined With Unsafe Actions | cvebase