First published: Wed Feb 01 2023(Updated: )
A DLL hijacking vulnerability exists in the BIG-IP Edge Client for Windows. User interaction and administrative privileges are required to exploit this vulnerability because the victim user needs to run the executable on the system and the attacker requires administrative privileges for modifying the files in the trusted search path.
Credit: f5sirt@f5.com f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Big-ip Access Policy Manager | >=7.2.2<7.2.3.1 | |
F5 Big-ip Access Policy Manager | >=13.1.0<=13.1.5 | |
F5 Big-ip Access Policy Manager | >=14.1.0<=14.1.5 | |
F5 Big-ip Access Policy Manager | >=15.1.0<=15.1.8 | |
F5 Big-ip Access Policy Manager | >=16.1.0<=16.1.3 | |
F5 Big-ip Access Policy Manager | >=17.0.0<17.0.0.2 | |
F5 Big-ip Edge | ||
F5 BIG-IP (APM) | =17.0.0 | 17.1.0 |
F5 BIG-IP (APM) | >=16.1.0<=16.1.3=3 | 16.1.3.4 |
F5 BIG-IP (APM) | >=15.1.0<=15.1.8=3 | 15.1.8.2 |
F5 BIG-IP (APM) | >=14.1.0<=14.1.5=3 | 14.1.5.4 |
F5 BIG-IP (APM) | >=13.1.0<=13.1.5=3 | |
F5 BIG-IP APM Clients | =7.2.2 | 7.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this DLL hijacking vulnerability is CVE-2023-22283.
The severity level of CVE-2023-22283 is medium (6.5).
Versions beginning in 7.1.5 to before 7.2.3.1 of the BIG-IP Edge Client for Windows are affected by CVE-2023-22283.
Yes, user interaction is required to exploit CVE-2023-22283.
You can find more information about CVE-2023-22283 at the following reference: https://my.f5.com/manage/s/article/K07143733.