ID

VAR-202302-0009


CVE

CVE-2023-22326


TITLE

BIG-IP  and   BIG-IQ  Vulnerability in improper permission assignment for critical resources in

Trust: 0.8

sources: JVNDB: JVNDB-2023-003201

DESCRIPTION

In BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, and all versions of BIG-IQ 8.x and 7.1.x, incorrect permission assignment vulnerabilities exist in the iControl REST and TMOS shell (tmsh) dig command which may allow an authenticated attacker with resource administrator or administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. BIG-IP and BIG-IQ Contains a vulnerability in improper permission assignment for critical resources.Information may be obtained

Trust: 1.8

sources: NVD: CVE-2023-22326 // JVNDB: JVNDB-2023-003201 // VULHUB: VHN-451919 // VULMON: CVE-2023-22326

AFFECTED PRODUCTS

vendor:f5model:big-ip policy enforcement managerscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:ltversion:15.1.8.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:ltversion:15.1.8.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:ltversion:15.1.8.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip application security managerscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:15.1.8.1

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:ltversion:15.1.8.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:15.1.8.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:15.1.8.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:15.1.8.1

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:15.1.8.1

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:15.1.8.1

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:ltversion:15.1.8.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:15.1.8.1

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope: - version: -

Trust: 0.8

vendor:f5model:big-ip application security managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip ddos hybrid defenderscope: - version: -

Trust: 0.8

vendor:f5model:big-ip access policy managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip fraud protection servicescope: - version: -

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip link controllerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip analyticsscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2023-003201 // NVD: CVE-2023-22326

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2023-22326
value: MEDIUM

Trust: 1.0

f5sirt@f5.com: CVE-2023-22326
value: MEDIUM

Trust: 1.0

OTHER: JVNDB-2023-003201
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202302-096
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2023-22326
baseSeverity: MEDIUM
baseScore: 4.9
vectorString: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.2
impactScore: 3.6
version: 3.1

Trust: 2.0

OTHER: JVNDB-2023-003201
baseSeverity: MEDIUM
baseScore: 4.9
vectorString: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2023-003201 // CNNVD: CNNVD-202302-096 // NVD: CVE-2023-22326 // NVD: CVE-2023-22326

PROBLEMTYPE DATA

problemtype:CWE-732

Trust: 1.1

problemtype:Improper permission assignment for critical resources (CWE-732) [NVD evaluation ]

Trust: 0.8

sources: VULHUB: VHN-451919 // JVNDB: JVNDB-2023-003201 // NVD: CVE-2023-22326

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202302-096

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202302-096

PATCH

title:K83284425url:https://my.f5.com/manage/s/article/K83284425

Trust: 0.8

title:F5 BIG-IP Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=224514

Trust: 0.6

title: - url:https://github.com/Live-Hack-CVE/CVE-2023-22326

Trust: 0.1

sources: VULMON: CVE-2023-22326 // JVNDB: JVNDB-2023-003201 // CNNVD: CNNVD-202302-096

EXTERNAL IDS

db:NVDid:CVE-2023-22326

Trust: 3.4

db:JVNDBid:JVNDB-2023-003201

Trust: 0.8

db:CNNVDid:CNNVD-202302-096

Trust: 0.6

db:VULHUBid:VHN-451919

Trust: 0.1

db:VULMONid:CVE-2023-22326

Trust: 0.1

sources: VULHUB: VHN-451919 // VULMON: CVE-2023-22326 // JVNDB: JVNDB-2023-003201 // CNNVD: CNNVD-202302-096 // NVD: CVE-2023-22326

REFERENCES

url:https://my.f5.com/manage/s/article/k83284425

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2023-22326

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2023-22326/

Trust: 0.6

url:https://github.com/live-hack-cve/cve-2023-22326

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-451919 // VULMON: CVE-2023-22326 // JVNDB: JVNDB-2023-003201 // CNNVD: CNNVD-202302-096 // NVD: CVE-2023-22326

SOURCES

db:VULHUBid:VHN-451919
db:VULMONid:CVE-2023-22326
db:JVNDBid:JVNDB-2023-003201
db:CNNVDid:CNNVD-202302-096
db:NVDid:CVE-2023-22326

LAST UPDATE DATE

2024-08-14T13:42:06.432000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-451919date:2023-02-09T00:00:00
db:VULMONid:CVE-2023-22326date:2023-02-01T00:00:00
db:JVNDBid:JVNDB-2023-003201date:2023-09-04T05:18:00
db:CNNVDid:CNNVD-202302-096date:2023-02-10T00:00:00
db:NVDid:CVE-2023-22326date:2023-11-07T04:06:50.377

SOURCES RELEASE DATE

db:VULHUBid:VHN-451919date:2023-02-01T00:00:00
db:VULMONid:CVE-2023-22326date:2023-02-01T00:00:00
db:JVNDBid:JVNDB-2023-003201date:2023-09-04T00:00:00
db:CNNVDid:CNNVD-202302-096date:2023-02-01T00:00:00
db:NVDid:CVE-2023-22326date:2023-02-01T18:15:10.977