First published: Wed Sep 27 2023(Updated: )
BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Credit: f5sirt@f5.com f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Big-ip Access Policy Manager | >=14.1.5.2<=14.1.5.6 | |
F5 Big-ip Access Policy Manager | >=15.1.8<=15.1.10 | |
F5 Big-ip Access Policy Manager | >=16.1.3.3<=16.1.4 | |
F5 Big-ip Access Policy Manager | =13.1.5.1 | |
F5 Big-ip Access Policy Manager | =17.1.0 | |
F5 Big-ip Access Policy Manager Client | >=7.2.3<=7.2.4 | |
F5 BIG-IP APM | >=17.1.0<=17.1.1 | 3 |
F5 BIG-IP APM | =16.1.3.3 | 3 |
F5 BIG-IP APM | =15.1.8 | 3 |
F5 BIG-IP APM | >=14.1.5.2<=14.1.5.6 | 3 |
F5 BIG-IP APM | =13.1.5.1 | 3 |
F5 APM Clients | >=7.2.3<=7.2.4 | 7.2.4.6 |
F5 F5 Access for iOS | >=3.0.13<=3.0.14 | |
F5 F5 Access for macOS | >=2.0.2<=2.0.3 | |
F5 F5 Access for Windows | >=1.2<=1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-43124 is a vulnerability in BIG-IP APM clients that allows them to send IP traffic outside of the VPN tunnel.
CVE-2023-43124 has a severity rating of 7.1 (high).
Software versions 14.1.5.2 to 14.1.5.6, 15.1.8 to 15.1.10, 16.1.3.3 to 16.1.4, 13.1.5.1, and 17.1.0 of F5 Big-ip Access Policy Manager are affected by CVE-2023-43124.
To fix CVE-2023-43124, update to a version of F5 Big-ip Access Policy Manager that is not affected by the vulnerability.
You can find more information about CVE-2023-43124 at the following link: [Reference](https://my.f5.com/manage/s/article/K000136907)