F5 Security Updates 02 February 2023

F5 has released security updates to fix several vulnerabilities across multiple F5 products.

The addressed vulnerabilities could allow the attacker to take control of the affected system by sending a specially crafted request to

disclose information, escalate privileges, or cause a denial of service attack.

Samples of the addressed vulnerabilities:

1. iControl SOAP Vulnerability (CVE-2023-22374):

• CVSS: 8.5

• Attack Vector: Network

• Attack Complexity: High

• Privileges Required: Low

• User Interaction: None

• Consequences: Gain Access

2. BIG-IP Virtual Edition Vulnerability (CVE-2023-23555):

• CVSS: 7.5

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: Low

• User Interaction: None

• Consequences: Denial of Service

Vulnerabilities
Mitigations

The enterprise should deploy the patch as soon as the testing phase is completed.

F5 Security Advisory

References