Undisclosed Requests Can Cause BD Process Termination in BIG-IP Advanced WAF and ASM
CVE-2024-23308
What is CVE-2024-23308?
A vulnerability exists in the F5 BIG-IP Advanced WAF and BIG-IP ASM that can lead to unexpected termination of the BD process when specific configurations are applied. This issue arises when a policy containing the Request Body Handling option is enabled for a virtual server. The profile must include 'Apply value and content signatures and detect threat campaigns' for an Allowed URL. Users utilizing software versions that have reached their End of Technical Support are not subject to this evaluation, emphasizing the need for timely updates and oversight in security practices. Admin attention is essential to mitigate these risks effectively.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
BIG-IP 17.1.0 < 17.1.1
BIG-IP 16.1.0
BIG-IP 15.1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved