6.1
CVE-2023-3470
- EPSS 0.07%
- Veröffentlicht 02.08.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:17:20
- Quelle f5sirt@f5.com
- Teams Watchlist Login
- Unerledigt Login
Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account. The predictable nature of the password allows an authenticated user with TMSH access to the BIG-IP system, or anyone with physical access to the FIPS HSM, the information required to generate the correct password. On vCMP systems, all Guests share the same deterministic password, allowing those with TMSH access on one Guest to access keys of a different Guest. The following BIG-IP hardware platforms are affected: 10350v-F, i5820-DF, i7820-DF, i15820-DF, 5250v-F, 7200v-F, 10200v-F, 6900-F, 8900-F, 11000-F, and 11050-F. The BIG-IP rSeries r5920-DF and r10920-DF are not affected, nor does the issue affect software FIPS implementations or network HSM configurations. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
F5 ≫ Big-ip Access Policy Manager Version >= 13.1.0 < 13.1.4
F5 ≫ Big-ip Access Policy Manager Version >= 14.1.0 < 14.1.4
F5 ≫ Big-ip Access Policy Manager Version15.1.0
F5 ≫ Big-ip Advanced Firewall Manager Version >= 13.1.0 < 13.1.4
F5 ≫ Big-ip Advanced Firewall Manager Version >= 14.1.0 < 14.1.4
F5 ≫ Big-ip Advanced Firewall Manager Version15.1.0
F5 ≫ Big-ip Advanced Web Application Firewall Version >= 13.1.0 < 13.1.4
F5 ≫ Big-ip Advanced Web Application Firewall Version >= 14.1.0 < 14.1.4
F5 ≫ Big-ip Advanced Web Application Firewall Version15.1.0
F5 ≫ Big-ip Analytics Version >= 13.1.0 < 13.1.4
F5 ≫ Big-ip Analytics Version >= 14.1.0 < 14.1.4
F5 ≫ Big-ip Analytics Version15.1.0
F5 ≫ Big-ip Application Acceleration Manager Version >= 13.1.0 < 13.1.4
F5 ≫ Big-ip Application Acceleration Manager Version >= 14.1.0 < 14.1.4
F5 ≫ Big-ip Application Acceleration Manager Version15.1.0
F5 ≫ Big-ip Application Security Manager Version >= 13.1.0 < 13.1.4
F5 ≫ Big-ip Application Security Manager Version >= 14.1.0 < 14.1.4
F5 ≫ Big-ip Application Security Manager Version15.1.0
F5 ≫ Big-ip Application Visibility And Reporting Version >= 13.1.0 < 13.1.4
F5 ≫ Big-ip Application Visibility And Reporting Version >= 14.1.0 < 14.1.4
F5 ≫ Big-ip Application Visibility And Reporting Version15.1.0
F5 ≫ Big-ip Carrier-grade Nat Version >= 13.1.0 < 13.1.4
F5 ≫ Big-ip Carrier-grade Nat Version >= 14.1.0 < 14.1.4
F5 ≫ Big-ip Carrier-grade Nat Version15.1.0
F5 ≫ Big-ip Ddos Hybrid Defender Version >= 13.1.0 < 13.1.4
F5 ≫ Big-ip Ddos Hybrid Defender Version >= 14.1.0 < 14.1.4
F5 ≫ Big-ip Ddos Hybrid Defender Version15.1.0
F5 ≫ Big-ip Domain Name System Version >= 13.1.0 < 13.1.4
F5 ≫ Big-ip Domain Name System Version >= 14.1.0 < 14.1.4
F5 ≫ Big-ip Domain Name System Version15.1.0
F5 ≫ Big-ip Edge Gateway Version >= 13.1.0 < 13.1.4
F5 ≫ Big-ip Edge Gateway Version >= 14.1.0 < 14.1.4
F5 ≫ Big-ip Edge Gateway Version15.1.0
F5 ≫ Big-ip Fraud Protection Service Version >= 13.1.0 < 13.1.4
F5 ≫ Big-ip Fraud Protection Service Version >= 14.1.0 < 14.1.4
F5 ≫ Big-ip Fraud Protection Service Version15.1.0
F5 ≫ Big-ip Global Traffic Manager Version >= 13.1.0 < 13.1.4
F5 ≫ Big-ip Global Traffic Manager Version >= 14.1.0 < 14.1.4
F5 ≫ Big-ip Global Traffic Manager Version15.1.0
F5 ≫ Big-ip Link Controller Version >= 13.1.0 < 13.1.4
F5 ≫ Big-ip Link Controller Version >= 14.1.0 < 14.1.4
F5 ≫ Big-ip Link Controller Version15.1.0
F5 ≫ Big-ip Local Traffic Manager Version >= 13.1.0 < 13.1.4
F5 ≫ Big-ip Local Traffic Manager Version >= 14.1.0 < 14.1.4
F5 ≫ Big-ip Local Traffic Manager Version15.1.0
F5 ≫ Big-ip Policy Enforcement Manager Version >= 13.1.0 < 13.1.4
F5 ≫ Big-ip Policy Enforcement Manager Version >= 14.1.0 < 14.1.4
F5 ≫ Big-ip Policy Enforcement Manager Version15.1.0
F5 ≫ Big-ip Ssl Orchestrator Version >= 13.1.0 < 13.1.4
F5 ≫ Big-ip Ssl Orchestrator Version >= 14.1.0 < 14.1.4
F5 ≫ Big-ip Ssl Orchestrator Version15.1.0
F5 ≫ Big-ip Webaccelerator Version >= 13.1.0 < 13.1.4
F5 ≫ Big-ip Webaccelerator Version >= 14.1.0 < 14.1.4
F5 ≫ Big-ip Webaccelerator Version15.1.0
F5 ≫ Big-ip Websafe Version >= 13.1.0 < 13.1.4
F5 ≫ Big-ip Websafe Version >= 14.1.0 < 14.1.4
F5 ≫ Big-ip Websafe Version15.1.0
F5 ≫ Big-ip 10350v-f Firmware Version-
F5 ≫ Big-ip I5820-df Firmware Version-
F5 ≫ Big-ip I7820-df Firmware Version-
F5 ≫ Big-ip I15820-df Firmware Version-
F5 ≫ Big-ip 5250v-f Firmware Version-
F5 ≫ Big-ip 7200v-f Firmware Version-
F5 ≫ Big-ip 10200v-f Firmware Version-
F5 ≫ Big-ip 6900-f Firmware Version-
F5 ≫ Big-ip 8900-f Firmware Version-
F5 ≫ Big-ip 11000-f Firmware Version-
F5 ≫ Big-ip 11050-f Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.07% | 0.224 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.1 | 0.9 | 5.2 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
f5sirt@f5.com | 6 | 0.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
|
CWE-1391 Use of Weak Credentials
The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.