CVE Vulnerabilities


Use of Externally-Controlled Format String

Published: Feb 01, 2023 | Modified: Oct 04, 2023
CVSS 3.x
CVSS 2.x

A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appliance mode BIG-IP, a successful exploit of this vulnerability can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.


The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Affected Software

Name Vendor Start Version End Version
Big-ip_access_policy_manager F5 (including) 14.1.5 (including)
Big-ip_access_policy_manager F5 (including) 15.1.8 (including)
Big-ip_access_policy_manager F5 (including) 16.1.3 (including)
Big-ip_access_policy_manager F5 13.1.5 (including) 13.1.5 (including)
Big-ip_access_policy_manager F5 17.0.0 (including) 17.0.0 (including)
Big-ip_advanced_firewall_manager F5 (including) 14.1.5 (including)
Big-ip_advanced_firewall_manager F5 (including) 15.1.8 (including)
Big-ip_advanced_firewall_manager F5 (including) 16.1.3 (including)
Big-ip_advanced_firewall_manager F5 13.1.5 (including) 13.1.5 (including)
Big-ip_advanced_firewall_manager F5 17.0.0 (including) 17.0.0 (including)
Big-ip_analytics F5 (including) 14.1.5 (including)
Big-ip_analytics F5 (including) 15.1.8 (including)
Big-ip_analytics F5 (including) 16.1.3 (including)
Big-ip_analytics F5 13.1.5 (including) 13.1.5 (including)
Big-ip_analytics F5 17.0.0 (including) 17.0.0 (including)
Big-ip_application_acceleration_manager F5 (including) 15.1.8 (including)
Big-ip_application_acceleration_manager F5 (including) 16.1.3 (including)
Big-ip_application_acceleration_manager F5 13.1.5 (including) 13.1.5 (including)
Big-ip_application_acceleration_manager F5 17.0.0 (including) 17.0.0 (including)
Big-ip_application_security_manager F5 (including) 14.1.5 (including)
Big-ip_application_security_manager F5 (including) 15.1.8 (including)
Big-ip_application_security_manager F5 (including) 16.1.3 (including)
Big-ip_application_security_manager F5 13.1.0 (including) 13.1.0 (including)
Big-ip_application_security_manager F5 17.0.0 (including) 17.0.0 (including)
Big-ip_ddos_hybrid_defender F5 (including) 14.1.5 (including)
Big-ip_ddos_hybrid_defender F5 (including) 15.1.8 (including)
Big-ip_ddos_hybrid_defender F5 (including) 16.1.3 (including)
Big-ip_ddos_hybrid_defender F5 13.1.5 (including) 13.1.5 (including)
Big-ip_domain_name_system F5 (including) 14.1.5 (including)
Big-ip_domain_name_system F5 (including) 15.1.8 (including)
Big-ip_domain_name_system F5 (including) 16.1.3 (including)
Big-ip_domain_name_system F5 17.0.0 (including) 17.0.0 (including)
Big-ip_fraud_protection_service F5 (including) 15.1.8 (including)
Big-ip_fraud_protection_service F5 (including) 16.1.3 (including)
Big-ip_fraud_protection_service F5 13.1.5 (including) 13.1.5 (including)
Big-ip_fraud_protection_service F5 17.0.0 (including) 17.0.0 (including)
Big-ip_link_controller F5 (including) 14.1.5 (including)
Big-ip_link_controller F5 (including) 15.1.8 (including)
Big-ip_link_controller F5 (including) 16.1.3 (including)
Big-ip_link_controller F5 13.1.5 (including) 13.1.5 (including)
Big-ip_link_controller F5 17.0.0 (including) 17.0.0 (including)
Big-ip_local_traffic_manager F5 (including) 14.1.5 (including)
Big-ip_local_traffic_manager F5 (including) 15.1.8 (including)
Big-ip_local_traffic_manager F5 (including) 16.1.3 (including)
Big-ip_local_traffic_manager F5 13.1.5 (including) 13.1.5 (including)
Big-ip_local_traffic_manager F5 17.0.0 (including) 17.0.0 (including)
Big-ip_policy_enforcement_manager F5 (including) 14.1.5 (including)
Big-ip_policy_enforcement_manager F5 (including) 15.1.8 (including)
Big-ip_policy_enforcement_manager F5 (including) 16.1.3 (including)
Big-ip_policy_enforcement_manager F5 13.1.5 (including) 13.1.5 (including)
Big-ip_policy_enforcement_manager F5 17.0.0 (including) 17.0.0 (including)
Big-ip_ssl_orchestrator F5 (including) 14.1.5 (including)
Big-ip_ssl_orchestrator F5 (including) 15.1.8 (including)
Big-ip_ssl_orchestrator F5 (including) 16.1.3 (including)
Big-ip_ssl_orchestrator F5 13.1.5 (including) 13.1.5 (including)
Big-ip_ssl_orchestrator F5 17.0.0 (including) 17.0.0 (including)

Extended Description

When an attacker can modify an externally-controlled format string, this can lead to buffer overflows, denial of service, or data representation problems. It should be noted that in some circumstances, such as internationalization, the set of format strings is externally controlled by design. If the source of these format strings is trusted (e.g. only contained in library files that are only modifiable by the system administrator), then the external control might not itself pose a vulnerability.

Potential Mitigations