CVE-2023-42772: High severity f5 big-ip and big-iq centralized management vulnerability
Published Sep 16, 2024
·Updated
Untrusted pointer dereference in UEFI firmware for some Intel(R) reference processors may allow a privileged user to potentially enable escalation of privilege via local access.
Affected Software
3 affected components
F5 BIG-IP>=17.1.0<=17.1.1
F5 BIG-IP>=16.1.0<=16.1.5
F5 BIG-IP>=15.1.0<=15.1.10
Event History
Sep 16, 2024
CVE Published
via MITRE·04:38 PM
Data Sourced
via MITRE·04:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Oct 19, 2024
Advisory Published
via F5·12:05 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-42772?
CVE-2023-42772 has been rated as a high severity vulnerability due to its potential for escalation of privilege.
2
How do I fix CVE-2023-42772?
To fix CVE-2023-42772, apply the latest firmware updates provided by F5 for the affected BIG-IP versions.
3
What impact does CVE-2023-42772 have on my system?
CVE-2023-42772 may allow a privileged user to gain elevated access and control over system resources.
4
Who is affected by CVE-2023-42772?
CVE-2023-42772 affects F5 BIG-IP users running versions 15.1.0 to 15.1.10, 16.1.0 to 16.1.5, and 17.1.0 to 17.1.1.
5
Is there a workaround for CVE-2023-42772?
Currently, there are no known workarounds for CVE-2023-42772, and it is recommended to upgrade to the patched versions.