cbcvebase.
CVE-2024-23308
published 2024-02-14

CVE-2024-23308: When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause the BD…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause the BD process to terminate. The condition results from setting the Request Body Handling option in the Header-Based Content Profile for an Allowed URL with "Apply value and content signatures and detect threat campaigns." Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Affected

5 ranges
VendorProductVersion rangeFixed in
f5big-ip>= 17.1.0 < 17.1.117.1.1
f5big-ip_advanced_waf
f5big-ip_advanced_web_application_firewall>= 17.1.0 < 17.1.117.1.1
f5big-ip_application_security_manager>= 17.1.0 < 17.1.117.1.1
f5big-ip_asm