ID

VAR-202302-0010


CVE

CVE-2023-22418


TITLE

BIG-IP APM  Open redirect vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2023-003164

DESCRIPTION

On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated malicious attacker to build an open redirect URI. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Trust: 1.8

sources: NVD: CVE-2023-22418 // JVNDB: JVNDB-2023-003164 // VULHUB: VHN-451924 // VULMON: CVE-2023-22418

AFFECTED PRODUCTS

vendor:f5model:big-ip policy enforcement managerscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:ltversion:15.1.7

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:15.1.7

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:ltversion:15.1.8.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:ltversion:15.1.7

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:15.1.7

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:15.1.7

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:15.1.7

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:ltversion:15.1.7

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:15.1.7

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip application security managerscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip fraud protection servicescope:ltversion:15.1.7

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:15.1.7

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip analyticsscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:ltversion:15.1.7

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:gteversion:15.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip domain name systemscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:17.0.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:14.1.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:ltversion:14.1.5.3

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:16.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:ltversion:17.0.0.2

Trust: 1.0

vendor:f5model:big-ip ddos hybrid defenderscope:lteversion:13.1.5

Trust: 1.0

vendor:f5model:big-ip link controllerscope:ltversion:16.1.3.3

Trust: 1.0

vendor:f5model:big-ip ssl orchestratorscope:gteversion:13.1.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip access policy managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip domain name systemscope: - version: -

Trust: 0.8

vendor:f5model:big-ip ddos hybrid defenderscope: - version: -

Trust: 0.8

vendor:f5model:big-ip analyticsscope: - version: -

Trust: 0.8

vendor:f5model:big-ip link controllerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip fraud protection servicescope: - version: -

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip application security managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2023-003164 // NVD: CVE-2023-22418

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2023-22418
value: MEDIUM

Trust: 1.0

f5sirt@f5.com: CVE-2023-22418
value: MEDIUM

Trust: 1.0

OTHER: JVNDB-2023-003164
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202302-091
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2023-22418
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.1

Trust: 2.0

OTHER: JVNDB-2023-003164
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2023-003164 // CNNVD: CNNVD-202302-091 // NVD: CVE-2023-22418 // NVD: CVE-2023-22418

PROBLEMTYPE DATA

problemtype:CWE-601

Trust: 1.1

problemtype:Open redirect (CWE-601) [NVD evaluation ]

Trust: 0.8

sources: VULHUB: VHN-451924 // JVNDB: JVNDB-2023-003164 // NVD: CVE-2023-22418

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202302-091

TYPE

input validation error

Trust: 0.6

sources: CNNVD: CNNVD-202302-091

PATCH

title:K95503300url:https://my.f5.com/manage/s/article/K95503300

Trust: 0.8

title:F5 BIG-IP Enter the fix for the verification error vulnerabilityurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=224509

Trust: 0.6

title: - url:https://github.com/Live-Hack-CVE/CVE-2023-22418

Trust: 0.1

sources: VULMON: CVE-2023-22418 // JVNDB: JVNDB-2023-003164 // CNNVD: CNNVD-202302-091

EXTERNAL IDS

db:NVDid:CVE-2023-22418

Trust: 3.4

db:JVNDBid:JVNDB-2023-003164

Trust: 0.8

db:CNNVDid:CNNVD-202302-091

Trust: 0.6

db:VULHUBid:VHN-451924

Trust: 0.1

db:VULMONid:CVE-2023-22418

Trust: 0.1

sources: VULHUB: VHN-451924 // VULMON: CVE-2023-22418 // JVNDB: JVNDB-2023-003164 // CNNVD: CNNVD-202302-091 // NVD: CVE-2023-22418

REFERENCES

url:https://my.f5.com/manage/s/article/k95503300

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2023-22418

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2023-22418/

Trust: 0.6

url:https://github.com/live-hack-cve/cve-2023-22418

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-451924 // VULMON: CVE-2023-22418 // JVNDB: JVNDB-2023-003164 // CNNVD: CNNVD-202302-091 // NVD: CVE-2023-22418

SOURCES

db:VULHUBid:VHN-451924
db:VULMONid:CVE-2023-22418
db:JVNDBid:JVNDB-2023-003164
db:CNNVDid:CNNVD-202302-091
db:NVDid:CVE-2023-22418

LAST UPDATE DATE

2024-08-14T15:26:53.132000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-451924date:2023-02-09T00:00:00
db:VULMONid:CVE-2023-22418date:2023-02-01T00:00:00
db:JVNDBid:JVNDB-2023-003164date:2023-09-01T07:46:00
db:CNNVDid:CNNVD-202302-091date:2023-02-10T00:00:00
db:NVDid:CVE-2023-22418date:2023-11-07T04:06:53.187

SOURCES RELEASE DATE

db:VULHUBid:VHN-451924date:2023-02-01T00:00:00
db:VULMONid:CVE-2023-22418date:2023-02-01T00:00:00
db:JVNDBid:JVNDB-2023-003164date:2023-09-01T00:00:00
db:CNNVDid:CNNVD-202302-091date:2023-02-01T00:00:00
db:NVDid:CVE-2023-22418date:2023-02-01T18:15:11.450