BIGIP and BIG-IQ TACACS+ audit log Vulnerability
CVE-2023-43485
5.5MEDIUM
What is CVE-2023-43485?
When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Version(s)
BIG-IP 16.1.0 < 16.1.4
BIG-IP 15.1.0 < 15.1.9
BIG-IP 14.1.0