imPC@ndo IT

Tracker / CVE-2023-22283

CVE-2023-22283

Medium 6.5

On versions beginning in 7.1.5 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client for Windows. User interaction and administrative privileges are required to exploit this vulnerability because the victim user needs to run the executable on the system and the attacker requires administrative privileges for modifying the files in the trusted search path. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected products and versions

f5 big-ip_access_policy_manager · 13.1.0 → 13.1.5
f5 big-ip_access_policy_manager · 14.1.0 → 14.1.5
f5 big-ip_access_policy_manager · 15.1.0 → 15.1.8
f5 big-ip_access_policy_manager · 16.1.0 → 16.1.3
f5 big-ip_access_policy_manager · 17.0.0 → 17.0.0.2
f5 big-ip_access_policy_manager · 7.2.2 → 7.2.3.1
f5 big-ip_edge

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References