CVE-2024-23976
published 2024-02-14CVE-2024-23976: When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing iAppsLX…
PriorityP427medium6CVSS 3.1
AVLACLPRHUINSUCHIHAN
EPSS
0.17%
6.3th percentile
When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance
mode restrictions utilizing iAppsLX templates on a BIG-IP system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | >= 15.1.0 < 15.1.9 | 15.1.9 |
| f5 | big-ip | >= 16.1.0 < 16.1.4 | 16.1.4 |
| f5 | big-ip | >= 17.1.0 < 17.1.1 | 17.1.1 |
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | >= 15.1.0 < 15.1.9 | 15.1.9 |
| f5 | big-ip_access_policy_manager | >= 16.1.0 < 16.1.4 | 16.1.4 |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | >= 15.1.0 < 15.1.9 | 15.1.9 |
| f5 | big-ip_advanced_firewall_manager | >= 16.1.0 < 16.1.4 | 16.1.4 |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | >= 15.1.0 < 15.1.9 | 15.1.9 |
| f5 | big-ip_analytics | >= 16.1.0 < 16.1.4 | 16.1.4 |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | >= 15.1.0 < 15.1.9 | 15.1.9 |
| f5 | big-ip_application_acceleration_manager | >= 16.1.0 < 16.1.4 | 16.1.4 |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | >= 15.1.0 < 15.1.9 | 15.1.9 |
| f5 | big-ip_application_security_manager | >= 16.1.0 < 16.1.4 | 16.1.4 |
| f5 | big-ip_asm | — | — |
| f5 | big-ip_dns | — | — |
| f5 | big-ip_domain_name_system | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gx7x-8xvv-gh38: When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance
mode restrictions utilizing
ghsa_unreviewed·2024-02-14
CVE-2024-23976 [MEDIUM] CWE-266 GHSA-gx7x-8xvv-gh38: When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance
mode restrictions utilizing
When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance
mode restrictions utilizing iAppsLX templates on a BIG-IP system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
F5
CVE-2024-23976: When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appli...
vendor_f5·2024-02-14·CVSS 6.0
CVE-2024-23976 [MEDIUM] CWE-266 CVE-2024-23976: When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appli...
CVE-2024-23976: When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appli...
When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance
mode restrictions utilizing iAppsLX templates on a BIG-IP system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Analytics, BIG-IP DNS, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IQ
Affected Versions: 15.1.0 - 15.1.9; 16.1.0 - 16.1.4; 17.1.0; 8.0.0 - 8.3.0
F5 Advisory Articles: K91054692
F5 References: https://my.f5.com/manage/s/article/K91054692
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-14
Published