CVE-2024-23805: F5 Application Visibility and Reporting module and BIG-IP Advanced WAF/ASM vulnerability
Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility and Reporting module, this may occur when the HTTP Analytics profile with URLs enabled under Collected Entities is configured on a virtual server and the DB variables avr.IncludeServerInURI or avr.CollectOnlyHostnameFromURI are enabled. For BIG-IP Advanced WAF and ASM, this may occur when either a DoS or Bot Defense profile is configured on a virtual server and the DB variables avr.IncludeServerInURI or avr.CollectOnlyHostnameFromURI are enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
F5 BIG-IP Application Visibility and Reportingto a version that resolves this vulnerability.Fixed in 17.1.1 - Upgrade
Upgrade
F5 BIG-IP Application Visibility and Reportingto a version that resolves this vulnerability.Fixed in 16.1.4 - Upgrade
Upgrade
F5 BIG-IP Application Visibility and Reportingto a version that resolves this vulnerability.Fixed in 15.1.10 - Configuration
Disable the DB variables avr.IncludeServerInURI and avr.CollectOnlyHostnameFromURI (they are not enabled by default) when using the HTTP Analytics profile with URLs enabled under Collected Entities (Application Visibility and Reporting module) or when using DoS/Bot Defense profiles (BIG-IP Advanced WAF/ASM) to prevent TMM termination.
F5 BIG-IP (Application Visibility and Reporting module / HTTP Analytics profile) DB variables avr.IncludeServerInURI and/or avr.CollectOnlyHostnameFromURI = disabled - Configuration
If you use the HTTP Analytics profile with URLs enabled under Collected Entities, change the HTTP Analytics profile so that Collect URLs is not enabled on the affected virtual servers.
F5 BIG-IP (HTTP Analytics profile) HTTP Analytics profile > Collected Entities > Collect URLs (URLs enabled) = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23805?
CVE-2024-23805 is classified as a critical vulnerability that may lead to service termination.
How do I fix CVE-2024-23805?
To remediate CVE-2024-23805, upgrade to version 17.1.1, 16.1.4, or 15.1.10 of the affected F5 software.
Which F5 products are affected by CVE-2024-23805?
CVE-2024-23805 affects F5 BIG-IP Advanced Web Application Firewall and Application Security Manager across specific version ranges.
What might happen if CVE-2024-23805 is exploited?
Exploitation of CVE-2024-23805 could cause the Traffic Management Microkernel to terminate, impacting application availability.
Is there a workaround for CVE-2024-23805?
There are no recommended workarounds for CVE-2024-23805; updating to a patched version is the only solution.