CVE Vulnerabilities

CVE-2023-22374

Use of Externally-Controlled Format String

Published: Feb 01, 2023 | Modified: Oct 04, 2023
CVSS 3.x
8.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appliance mode BIG-IP, a successful exploit of this vulnerability can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Weakness

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Affected Software

Name Vendor Start Version End Version
Big-ip_access_policy_manager F5 14.1.4.6 (including) 14.1.5 (including)
Big-ip_access_policy_manager F5 15.1.5.1 (including) 15.1.8 (including)
Big-ip_access_policy_manager F5 16.1.2.2 (including) 16.1.3 (including)
Big-ip_access_policy_manager F5 13.1.5 (including) 13.1.5 (including)
Big-ip_access_policy_manager F5 17.0.0 (including) 17.0.0 (including)
Big-ip_advanced_firewall_manager F5 14.1.4.6 (including) 14.1.5 (including)
Big-ip_advanced_firewall_manager F5 15.1.5.1 (including) 15.1.8 (including)
Big-ip_advanced_firewall_manager F5 16.1.2.2 (including) 16.1.3 (including)
Big-ip_advanced_firewall_manager F5 13.1.5 (including) 13.1.5 (including)
Big-ip_advanced_firewall_manager F5 17.0.0 (including) 17.0.0 (including)
Big-ip_analytics F5 14.1.4.6 (including) 14.1.5 (including)
Big-ip_analytics F5 15.1.5.1 (including) 15.1.8 (including)
Big-ip_analytics F5 16.1.2.2 (including) 16.1.3 (including)
Big-ip_analytics F5 13.1.5 (including) 13.1.5 (including)
Big-ip_analytics F5 17.0.0 (including) 17.0.0 (including)
Big-ip_application_acceleration_manager F5 15.1.5.1 (including) 15.1.8 (including)
Big-ip_application_acceleration_manager F5 16.1.2.2 (including) 16.1.3 (including)
Big-ip_application_acceleration_manager F5 13.1.5 (including) 13.1.5 (including)
Big-ip_application_acceleration_manager F5 17.0.0 (including) 17.0.0 (including)
Big-ip_application_security_manager F5 14.1.4.6 (including) 14.1.5 (including)
Big-ip_application_security_manager F5 15.1.5.1 (including) 15.1.8 (including)
Big-ip_application_security_manager F5 16.1.2.2 (including) 16.1.3 (including)
Big-ip_application_security_manager F5 13.1.0 (including) 13.1.0 (including)
Big-ip_application_security_manager F5 17.0.0 (including) 17.0.0 (including)
Big-ip_ddos_hybrid_defender F5 14.1.4.6 (including) 14.1.5 (including)
Big-ip_ddos_hybrid_defender F5 15.1.5.1 (including) 15.1.8 (including)
Big-ip_ddos_hybrid_defender F5 16.1.2.2 (including) 16.1.3 (including)
Big-ip_ddos_hybrid_defender F5 13.1.5 (including) 13.1.5 (including)
Big-ip_domain_name_system F5 14.1.4.6 (including) 14.1.5 (including)
Big-ip_domain_name_system F5 15.1.5.1 (including) 15.1.8 (including)
Big-ip_domain_name_system F5 16.1.2.2 (including) 16.1.3 (including)
Big-ip_domain_name_system F5 17.0.0 (including) 17.0.0 (including)
Big-ip_fraud_protection_service F5 15.1.5.1 (including) 15.1.8 (including)
Big-ip_fraud_protection_service F5 16.1.2.2 (including) 16.1.3 (including)
Big-ip_fraud_protection_service F5 13.1.5 (including) 13.1.5 (including)
Big-ip_fraud_protection_service F5 17.0.0 (including) 17.0.0 (including)
Big-ip_link_controller F5 14.1.4.6 (including) 14.1.5 (including)
Big-ip_link_controller F5 15.1.5.1 (including) 15.1.8 (including)
Big-ip_link_controller F5 16.1.2.2 (including) 16.1.3 (including)
Big-ip_link_controller F5 13.1.5 (including) 13.1.5 (including)
Big-ip_link_controller F5 17.0.0 (including) 17.0.0 (including)
Big-ip_local_traffic_manager F5 14.1.4.6 (including) 14.1.5 (including)
Big-ip_local_traffic_manager F5 15.1.5.1 (including) 15.1.8 (including)
Big-ip_local_traffic_manager F5 16.1.2.2 (including) 16.1.3 (including)
Big-ip_local_traffic_manager F5 13.1.5 (including) 13.1.5 (including)
Big-ip_local_traffic_manager F5 17.0.0 (including) 17.0.0 (including)
Big-ip_policy_enforcement_manager F5 14.1.4.6 (including) 14.1.5 (including)
Big-ip_policy_enforcement_manager F5 15.1.5.1 (including) 15.1.8 (including)
Big-ip_policy_enforcement_manager F5 16.1.2.2 (including) 16.1.3 (including)
Big-ip_policy_enforcement_manager F5 13.1.5 (including) 13.1.5 (including)
Big-ip_policy_enforcement_manager F5 17.0.0 (including) 17.0.0 (including)
Big-ip_ssl_orchestrator F5 14.1.4.6 (including) 14.1.5 (including)
Big-ip_ssl_orchestrator F5 15.1.5.1 (including) 15.1.8 (including)
Big-ip_ssl_orchestrator F5 16.1.2.2 (including) 16.1.3 (including)
Big-ip_ssl_orchestrator F5 13.1.5 (including) 13.1.5 (including)
Big-ip_ssl_orchestrator F5 17.0.0 (including) 17.0.0 (including)

Extended Description

When an attacker can modify an externally-controlled format string, this can lead to buffer overflows, denial of service, or data representation problems. It should be noted that in some circumstances, such as internationalization, the set of format strings is externally controlled by design. If the source of these format strings is trusted (e.g. only contained in library files that are only modifiable by the system administrator), then the external control might not itself pose a vulnerability.

Potential Mitigations

References