CVE-2023-43746 — Privilege Defined With Unsafe Actions in F5 Big-ip Application Security Manager
Severity
8.7HIGHNVD
EPSS
0.1%
top 82.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 10
Description
When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing BIG-IP external monitor on a BIG-IP system. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:NExploitability: 2.3 | Impact: 5.8
Affected Packages19 packages
🔴Vulnerability Details
2📋Vendor Advisories
1F5▶
CVE-2023-43746: When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance...↗2023-10-10