F5 (BIG-IP, NGINX) Products February 2024 1st Security Update Advisory
Overview
F5(https://www.f5.com/) has released a security update that addresses a vulnerability in its products. users of affected products are encouraged to update to the latest version.
Affected Products
Application Visibility and Reporting module and BIG-IP (Advanced WAF/ASM) 15.1.0 – 15.1.9
Application Visibility and Reporting module and BIG-IP (Advanced WAF/ASM) 16.1.0 – 16.1.3
Application Visibility and Reporting module and BIG-IP (Advanced WAF/ASM) 17.1.0
Big-ip (afm + ips) 15.1.0 – 15.1.8
Big-ip (afm + ips) 16.1.0 – 16.1.3
Big-ip (afm + ips) 17.1.0
Big-ip (afm) 15.1.0 – 15.1.9
Big-ip (afm) 16.1.0 – 16.1.3
Big-ip (afm) 17.1.0
BIG-IP (Advanced WAF/ASM) 16.1.0 – 16.1.3
BIG-IP (Advanced WAF/ASM) 17.1.0
Big-ip (pem) 15.1.0 – 15.1.103
Big-ip (pem) 16.1.0 – 16.1.43
Big-ip (pem) 17.1.0 – 17.1.13
Big-ip 15.1.0 – 15.1.8
Big-ip 15.1.0 – 15.1.9
Big-ip 16.1.0 – 16.1.3
BIG-IP 17.1.0
BIG-IP Next SPK 1.5.0 – 1.8.0
NGINX Open Source 1.25.0 – 1.25.3
NGINX Open Source 1.25.3
NGINX Plus R31
NGINX Plus R31 and R30
Resolved Vulnerabilities
Denial of Service Vulnerability in BIG-IP (PEM) due to a crafted request (CVE-2024-23982, CVSS 7.5) [1]
Denial of Service Vulnerability in BIG-IP (Advanced WAF/ASM) due to increased memory resources (CVE-2024-21789, CVSS 7.5) [2]
Denial of Service Vulnerability in BIG-IP (AFM) (CVE-2024-21763, CVSS 7.5) [3]
Denial of Service Vulnerability in the Application Visibility and Reporting module and BIG-IP (Advanced WAF/ASM) due to crafted requests (CVE-2024-23805, CVSS 7.5) [4]
Denial of Service Vulnerability in BIG-IP due to crafted traffic (CVE-2024-24775, CVSS 7.5) [5]
Denial of Service Vulnerability in BIG-IP Next SPK (CVE-2024-23314, CVSS 7.5) [6]
Denial of Service Vulnerability in BIG-IP (CVE-2024-23314, CVSS 7.5) [6]
Denial of Service Vulnerability in NGINX Open Source due to a crafted request (CVE-2024-24990, CVSS 7.5) [7]
Denial of Service Vulnerability in NGINX Plus due to a crafted request (CVE-2024-24990, CVSS 7.5) [7]
Denial of Service Vulnerability in NGINX Open Source due to a crafted request (CVE-2024-24989, CVSS 7.5) [8]
Denial of Service Vulnerability in NGINX Plus due to a crafted request (CVE-2024-24989, CVSS 7.5) [8]
Arbitrary code execution vulnerability due to crafted iControl REST in BIG-IP (CVE-2024-22093, CVSS 8.7) [9]
Denial of Service (DoS) Vulnerability in BIG-IP (Advanced WAF/ASM) due to crafted requests (CVE-2024-23308, CVSS 7.5) [10]
Denial of Service Vulnerability due to increased CPU utilization in BIG-IP (CVE-2024-23979, CVSS 7.5) [11]
Denial of Service Vulnerability in BIG-IP (Advanced WAF/ASM) due to crafted traffic (CVE-2024-21849, CVSS 7.5) [12]
Vulnerability in BIG-IP (AFM + IPS) (CVE-2024-21771, CVSS 7.5) [13]
Vulnerability in BIG-IP (CVE-2024-22389, CVSS 7.2) [14] [15]
Vulnerability Patches
Please follow the security advisory published on February 14 to update to the appropriate version and the latest version.
Application Visibility and Reporting module and BIG-IP (Advanced WAF/ASM) 15.1.10
Application Visibility and Reporting module and BIG-IP (Advanced WAF/ASM) 16.1.4
Application Visibility and Reporting module and BIG-IP (Advanced WAF/ASM) 17.1.1
Big-ip (afm + ips) 15.1.9
Big-ip (afm + ips) 16.1.4
Big-ip (afm + ips) 17.1.1
Big-ip (afm) 15.1.10
Big-ip (afm) 16.1.4
Big-ip (afm) 17.1.1
BIG-IP (Advanced WAF/ASM) 16.1.4
BIG-IP (Advanced WAF/ASM) 17.1.0
BIG-IP (Advanced WAF/ASM) 17.1.1
BIG-IP 15.1.10
BIG-IP 15.1.9
BIG-IP 16.1.4
BIG-IP 17.1.1
BIG-IP Next SPK 1.8.1
NGINX Open Source 1.25.4
NGINX Plus R31 P1
NGINX Plus R31 P1 and R30 P2
Reference Sites
[1] K000135946: BIG-IP PEM vulnerability CVE-2024-23982
https://my.f5.com/manage/s/article/K000135946
[2] K000137270: BIG-IP Advanced WAF and BIG-IP ASM and vulnerability CVE-2024-21789
https://my.f5.com/manage/s/article/K000137270
[3] K000137521: BIG-IP AFM vulnerability CVE-2024-21763
https://my.f5.com/manage/s/article/K000137521
[4] K000137334: F5 Application Visibility and Reporting module and BIG-IP Advanced WAF/ASM vulnerability CVE-2024-23805
https://my.f5.com/manage/s/article/K000137334
[5] K000137333: BIG-IP TMM vulnerability CVE-2024-24775
https://my.f5.com/manage/s/article/K000137333
[6] K000137675: BIG-IP HTTP/2 vulnerability CVE-2024-23314
https://my.f5.com/manage/s/article/K000137675
[7] K000138445: NGINX HTTP/3 QUIC vulnerability CVE-2024-24990
https://my.f5.com/manage/s/article/K000138445
[8] K000138444: NGINX HTTP/3 QUIC vulnerability CVE-2024-24989
https://my.f5.com/manage/s/article/K000138444
[9] K000137522: BIG-IP iControl REST vulnerability CVE-2024-22093
https://my.f5.com/manage/s/article/K000137522
[10] K000137416: BIG-IP Advanced WAF and BIG-IP ASM vulnerability CVE-2024-23308
https://my.f5.com/manage/s/article/K000137416
[11] K000134516: BIG-IP SSL Client Certificate LDAP and CRLDP Authentication profiles vulnerability CVE-2024-23979
https://my.f5.com/manage/s/article/K000134516
[12] K000135873: BIG-IP Websockets vulnerability CVE-2024-21849
https://my.f5.com/manage/s/article/K000135873
[13] K000137595: BIG-IP AFM signature matching vulnerability CVE-2024-21771
https://my.f5.com/manage/s/article/K000137595
[14] K32544615: BIG-IP iControl REST API vulnerability CVE-2024-22389