F5-K20307245: Medium severity f5 big-ip and big-iq centralized management vulnerability
Published Oct 10, 2023
·Updated
Exposure of Sensitive Information vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command, which may allow an authenticated attacker with resource administrator role privileges to view sensitive information.
Affected Software
5 affected componentsFixes available
F5 BIG-IP
17.1.0
F5 BIG-IP>=16.1.0<=16.1.3
16.1.4
F5 BIG-IP>=15.1.0<=15.1.8
15.1.9
F5 BIG-IP>=14.1.0<=14.1.5
F5 BIG-IP>=13.1.0<=13.1.5
Event History
Oct 10, 2023
Advisory Published
via F5·09:45 AM
Frequently Asked Questions
1
What is the severity of F5-K20307245?
The severity of F5-K20307245 is critical due to the potential exposure of sensitive information.
2
How do I fix F5-K20307245?
To mitigate the F5-K20307245 vulnerability, you should upgrade your BIG-IP system to a fixed version as recommended by F5.
3
Who is affected by F5-K20307245?
F5-K20307245 affects BIG-IP users with the resource administrator role privileges.
4
What types of information are exposed in F5-K20307245?
The F5-K20307245 vulnerability may allow attackers to view sensitive information through an undisclosed command.
5
Is there a workaround for F5-K20307245?
Currently, there is no documented workaround for F5-K20307245, so applying the available updates is recommended.