BIG-IP iControl REST vulnerability
CVE-2023-42768

7.2HIGH

Key Information:

Vendor

F5

Status
Vendor
CVE Published:
10 October 2023

What is CVE-2023-42768?

A security vulnerability exists within F5's BIG-IP product where non-admin users who have been mistakenly assigned administrator roles can maintain access to privileged iControl REST resources. This situation arises when the user’s role is reverted to non-admin through various methods including the Configuration utility, tmsh, or iControl REST, but the access rights erroneously persist. This loophole poses a significant risk of unauthorized access, allowing lower-privileged users to exploit elevated rights if their roles are not properly restricted.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

BIG-IP 16.1.0 < 16.1.4

BIG-IP 15.1.0 < 15.1.9

BIG-IP 14.1.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

F5
.