BIG-IP iControl REST vulnerability
CVE-2023-42768
What is CVE-2023-42768?
A security vulnerability exists within F5's BIG-IP product where non-admin users who have been mistakenly assigned administrator roles can maintain access to privileged iControl REST resources. This situation arises when the user’s role is reverted to non-admin through various methods including the Configuration utility, tmsh, or iControl REST, but the access rights erroneously persist. This loophole poses a significant risk of unauthorized access, allowing lower-privileged users to exploit elevated rights if their roles are not properly restricted.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
BIG-IP 16.1.0 < 16.1.4
BIG-IP 15.1.0 < 15.1.9
BIG-IP 14.1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved