Undisclosed Requests Can Cause BD Process Termination in BIG-IP Advanced WAF and ASM
CVE-2024-23308
7.5HIGH
Summary
A vulnerability exists in the F5 BIG-IP Advanced WAF and BIG-IP ASM that can lead to unexpected termination of the BD process when specific configurations are applied. This issue arises when a policy containing the Request Body Handling option is enabled for a virtual server. The profile must include 'Apply value and content signatures and detect threat campaigns' for an Allowed URL. Users utilizing software versions that have reached their End of Technical Support are not subject to this evaluation, emphasizing the need for timely updates and oversight in security practices. Admin attention is essential to mitigate these risks effectively.
Affected Version(s)
BIG-IP 17.1.0 < 17.1.1
BIG-IP 16.1.0
BIG-IP 15.1.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
F5