Rewterz Threat Advisory – CVE-2023-20583 – AMD EPYC and Ryzen Processors Vulnerability
August 3, 2023Rewterz Threat Alert – Mirai Botnet aka Katana – Active IOCs
August 3, 2023Rewterz Threat Advisory – CVE-2023-20583 – AMD EPYC and Ryzen Processors Vulnerability
August 3, 2023Rewterz Threat Alert – Mirai Botnet aka Katana – Active IOCs
August 3, 2023Severity
Medium
Analysis Summary
CVE-2023-38418 CVSS:7.8
F5 BIG-IP (APM) could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper verification of cryptographic signature during the installation process. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges.
CVE-2023-36858 CVSS:7.1
F5 BIG-IP (APM) could allow a local authenticated attacker to bypass security restrictions, caused by an in insufficient verification of data. By sending a specially crafted request, an attacker could exploit this vulnerability to modify configured server list.
CVE-2023-3470 CVSS:6
F5 BIG-IP could allow a local authenticated attacker to obtain sensitive information, caused by a flaw when using Cavium Nitrox FIPS HSM cards to generate passwords. By utilize cryptographic attack techniques, an attacker could exploit this vulnerability to obtain password information for the Crypto User account, and use this information to launch further attacks against the affected system.
CVE-2023-38419 CVSS:4.3
F5 BIG-IP and BIG-IQ Centralized Management is vulnerable to a denial of service. By sending undisclosed requests, a remote authenticated attacker could exploit this vulnerability to cause the iControl SOAP process to terminate.
CVE-2023-36494 CVSS:4.4
F5 F5 F5OS-A could allow a local authenticated attacker to obtain sensitive information, caused by storing sensitive information into audit logs. By accessing the audit logs, an attacker could exploit this vulnerability to obtain sensitive information.
CVE-2023-38423 CVSS:5.4
F5 BIG-IP is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by an undisclosed page of the BIG-IP Configuration utility. A remote authenticated attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
Impact
- Privilege Escalation
- Denial of Service
- Security Bypass
- Information Disclosure
- Cross-Site Scripting
Indicators Of Compromise
CVE
- CVE-2023-38418
- CVE-2023-36858
- CVE-2023-3470
- CVE-2023-38419
- CVE-2023-36494
- CVE-2023-38423
Affected Vendors
F5
Affected Products
- F5 BIG-IP (APM) 14.1.0
- F5 BIG-IP (APM) 13.1.0
- F5 BIG-IP (APM) 15.1.0
- F5 BIG-IP (APM) 16.1.0
- F5 BIG-IP (APM) 13.1.5
- F5 BIG-IP (APM) 14.1.5
- F5 BIG-IP (APM) 16.1.3
- F5 BIG-IP (APM) 17.0.0
- F5 BIG-IP (APM) 17.1.0
- F5 BIG-IP (APM) 15.1.9
- F5 BIG-IP 13.1.0
- F5 BIG-IP 15.1.0
- F5 BIG-IP 14.1.0
- F5 BIG-IP 16.1.0
- F5 BIG-IP 16.1.3
- F5 BIG-IP 14.1.5
- F5 BIG-IQ Centralized Management 8.2.0
- F5 BIG-IP 15.1.9
- F5 BIG-IP 17.1.0
- F5 BIG-IQ Centralized Management 8.3.0
- F5 F5OS-A 1.4.0
Remediation
Refer to F5 Web site for patch, upgrade or suggested workaround information.