
Cloud Vulnerability DB
A community-led vulnerabilities database
An SQL injection vulnerability (CVE-2024-23603) exists in an undisclosed page of the BIG-IP Configuration utility. The vulnerability affects BIG-IP (Advanced WAF/ASM) versions 17.1.0, 16.1.0 through 16.1.3, and 15.1.0 through 15.1.9 (NVD, ASEC).
The vulnerability is specifically present in the BIG-IP Configuration utility, affecting Advanced WAF and ASM modules. The issue has been identified as an SQL injection vulnerability, though specific technical details about the exploitation method have not been publicly disclosed (CERT-FR).
While specific impact details are limited in public sources, as an SQL injection vulnerability, it could potentially lead to unauthorized access to the database, data manipulation, or exposure of sensitive information in the BIG-IP Configuration utility (ASEC).
F5 has released patches to address this vulnerability. Users are advised to upgrade to the following patched versions: BIG-IP (Advanced WAF/ASM) version 17.1.1, version 16.1.4, or version 15.1.10 (ASEC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."