Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
High
CVE-2023-22842 CVSS:7.5
F5 BIG-IP is vulnerable to a denial of service, caused by a flaw when a SIP profile is configured on a Message Routing type virtual server. By sending a specially-crafted traffic, a remote attacker could exploit this vulnerability to cause the Traffic Management Microkernel (TMM) to terminate, and results in a denial of service condition.
CVE-2023-22323 CVSS:7.5
F5 BIG-IP is vulnerable to a denial of service, caused by a flaw when OCSP authentication profile is configured on a virtual server. By sending specially-crafted requests, a remote attacker could exploit this vulnerability to cause an increase in CPU resource utilization, and results in a denial of service condition.
CVE-2023-22281 CVSS:7.5
F5 BIG-IP (AFM) is vulnerable to a denial of service, caused by a flawwhen NAT policy with a destination NAT rule is configured on a FastL4 virtual server. By sending a specially-crafted traffic, a remote attacker could exploit this vulnerability to cause the Traffic Management Microkernel (TMM) to terminate, and results in a denial of service condition.
CVE-2023-22422 CVSS:7.5
F5 BIG-IP is vulnerable to a denial of service, caused by a HTTP profile vulnerability. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause the Traffic Management Microkernel (TMM) to terminate.
CVE-2023-22358 CVSS:6.6
F5 BIG-IP (APM) could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper loading of Dynamic Link Libraries by the installer. By using a specially-crafted .DLL file, an authenticated attacker could exploit this vulnerability to gain administrative privileges.
CVE-2023-22664 CVSS:7.5
F5 BIG-IP is vulnerable to a denial of service, caused by a flaw when a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server. By sending specially-crafted requests, a remote attacker could exploit this vulnerability to cause an increase in memory resource utilization, and results in a denial of service condition.
CVE-2023-22340 CVSS:7.5
F5 BIG-IP is vulnerable to a denial of service, caused by a flaw when a SIP profile is configured on a Message Routing type virtual server. By sending a specially-crafted traffic, a remote attacker could exploit this vulnerability to cause TMM to terminate, and results in a denial of service condition.
CVE-2023-22341 CVSS:7.5
F5 BIG-IP (APM) is vulnerable to a denial of service, caused by a flaw in the OAuth profile configurations By sending specially-crafted requests, a remote attacker could exploit this vulnerability to cause the Traffic Management Microkernel (TMM) to terminate, and results in a denial of service condition.
CVE-2023-23555 CVSS:7.5
F5 BIG-IP is vulnerable to a denial of service, caused by a flaw in BIG-IP Virtual Edition. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause the Traffic Management Microkernel (TMM) to terminate.
CVE-2023-23552 CVSS:7.5
F5 BIG-IP (ASM) is vulnerable to a denial of service, caused by a flaw when a BIG-IP Advanced WAF or BIG-IP ASM security policy is configured on a virtual server. By sending specially-crafted requests, a remote attacker could exploit this vulnerability to cause an increase in memory resource utilization, and results in a denial of service condition.
CVE-2023-22374 CVSS:7.5
F5 BIG-IP could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a format string flaw in the iControl SOAP. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code or crash the iControl SOAP CGI process on the system.
F5
Refer to F5 Security Advisory for patch, upgrade or suggested workaround information.