Undisclosed Requests Can Cause BD Process Termination in BIG-IP Advanced WAF and ASM
CVE-2024-23308

7.5HIGH

Key Information:

Vendor
F5
Status
Vendor
CVE Published:
14 February 2024

Summary

A vulnerability exists in the F5 BIG-IP Advanced WAF and BIG-IP ASM that can lead to unexpected termination of the BD process when specific configurations are applied. This issue arises when a policy containing the Request Body Handling option is enabled for a virtual server. The profile must include 'Apply value and content signatures and detect threat campaigns' for an Allowed URL. Users utilizing software versions that have reached their End of Technical Support are not subject to this evaluation, emphasizing the need for timely updates and oversight in security practices. Admin attention is essential to mitigate these risks effectively.

Affected Version(s)

BIG-IP 17.1.0 < 17.1.1

BIG-IP 16.1.0

BIG-IP 15.1.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

F5
.