First published: Tue Oct 10 2023(Updated: )
Exposure of Sensitive Information vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command, which may allow an authenticated attacker with resource administrator role privileges to view sensitive information.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP and BIG-IQ Centralized Management | 17.1.0 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=16.1.0<=16.1.3 | 16.1.4 |
F5 BIG-IP and BIG-IQ Centralized Management | >=15.1.0<=15.1.8 | 15.1.9 |
F5 BIG-IP and BIG-IQ Centralized Management | >=14.1.0<=14.1.5 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=13.1.0<=13.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of F5-K20307245 is critical due to the potential exposure of sensitive information.
To mitigate the F5-K20307245 vulnerability, you should upgrade your BIG-IP system to a fixed version as recommended by F5.
F5-K20307245 affects BIG-IP users with the resource administrator role privileges.
The F5-K20307245 vulnerability may allow attackers to view sensitive information through an undisclosed command.
Currently, there is no documented workaround for F5-K20307245, so applying the available updates is recommended.