F5 (BIG-IP, NGINX) Products February 2024 1st Security Update Advisory

Overview

 

F5(https://www.f5.com/) has released a security update that addresses a vulnerability in its products. users of affected products are encouraged to update to the latest version.

 

Affected Products

 

Application Visibility and Reporting module and BIG-IP (Advanced WAF/ASM) 15.1.0 – 15.1.9

Application Visibility and Reporting module and BIG-IP (Advanced WAF/ASM) 16.1.0 – 16.1.3

Application Visibility and Reporting module and BIG-IP (Advanced WAF/ASM) 17.1.0

Big-ip (afm + ips) 15.1.0 – 15.1.8

Big-ip (afm + ips) 16.1.0 – 16.1.3

Big-ip (afm + ips) 17.1.0

Big-ip (afm) 15.1.0 – 15.1.9

Big-ip (afm) 16.1.0 – 16.1.3

Big-ip (afm) 17.1.0

BIG-IP (Advanced WAF/ASM) 16.1.0 – 16.1.3

BIG-IP (Advanced WAF/ASM) 17.1.0

Big-ip (pem) 15.1.0 – 15.1.103

Big-ip (pem) 16.1.0 – 16.1.43

Big-ip (pem) 17.1.0 – 17.1.13

Big-ip 15.1.0 – 15.1.8

Big-ip 15.1.0 – 15.1.9

Big-ip 16.1.0 – 16.1.3

BIG-IP 17.1.0

BIG-IP Next SPK 1.5.0 – 1.8.0

NGINX Open Source 1.25.0 – 1.25.3

NGINX Open Source 1.25.3

NGINX Plus R31

NGINX Plus R31 and R30

 

Resolved Vulnerabilities

 

Denial of Service Vulnerability in BIG-IP (PEM) due to a crafted request (CVE-2024-23982, CVSS 7.5) [1]

Denial of Service Vulnerability in BIG-IP (Advanced WAF/ASM) due to increased memory resources (CVE-2024-21789, CVSS 7.5) [2]

Denial of Service Vulnerability in BIG-IP (AFM) (CVE-2024-21763, CVSS 7.5) [3]

Denial of Service Vulnerability in the Application Visibility and Reporting module and BIG-IP (Advanced WAF/ASM) due to crafted requests (CVE-2024-23805, CVSS 7.5) [4]

Denial of Service Vulnerability in BIG-IP due to crafted traffic (CVE-2024-24775, CVSS 7.5) [5]

Denial of Service Vulnerability in BIG-IP Next SPK (CVE-2024-23314, CVSS 7.5) [6]

Denial of Service Vulnerability in BIG-IP (CVE-2024-23314, CVSS 7.5) [6]

Denial of Service Vulnerability in NGINX Open Source due to a crafted request (CVE-2024-24990, CVSS 7.5) [7]

Denial of Service Vulnerability in NGINX Plus due to a crafted request (CVE-2024-24990, CVSS 7.5) [7]

Denial of Service Vulnerability in NGINX Open Source due to a crafted request (CVE-2024-24989, CVSS 7.5) [8]

Denial of Service Vulnerability in NGINX Plus due to a crafted request (CVE-2024-24989, CVSS 7.5) [8]

Arbitrary code execution vulnerability due to crafted iControl REST in BIG-IP (CVE-2024-22093, CVSS 8.7) [9]

Denial of Service (DoS) Vulnerability in BIG-IP (Advanced WAF/ASM) due to crafted requests (CVE-2024-23308, CVSS 7.5) [10]

Denial of Service Vulnerability due to increased CPU utilization in BIG-IP (CVE-2024-23979, CVSS 7.5) [11]

Denial of Service Vulnerability in BIG-IP (Advanced WAF/ASM) due to crafted traffic (CVE-2024-21849, CVSS 7.5) [12]

Vulnerability in BIG-IP (AFM + IPS) (CVE-2024-21771, CVSS 7.5) [13]

Vulnerability in BIG-IP (CVE-2024-22389, CVSS 7.2) [14] [15]

 

Vulnerability Patches

 

Please follow the security advisory published on February 14 to update to the appropriate version and the latest version.

Application Visibility and Reporting module and BIG-IP (Advanced WAF/ASM) 15.1.10

Application Visibility and Reporting module and BIG-IP (Advanced WAF/ASM) 16.1.4

Application Visibility and Reporting module and BIG-IP (Advanced WAF/ASM) 17.1.1

Big-ip (afm + ips) 15.1.9

Big-ip (afm + ips) 16.1.4

Big-ip (afm + ips) 17.1.1

Big-ip (afm) 15.1.10

Big-ip (afm) 16.1.4

Big-ip (afm) 17.1.1

BIG-IP (Advanced WAF/ASM) 16.1.4

BIG-IP (Advanced WAF/ASM) 17.1.0

BIG-IP (Advanced WAF/ASM) 17.1.1

BIG-IP 15.1.10

BIG-IP 15.1.9

BIG-IP 16.1.4

BIG-IP 17.1.1

BIG-IP Next SPK 1.8.1

NGINX Open Source 1.25.4

NGINX Plus R31 P1

NGINX Plus R31 P1 and R30 P2

 

Reference Sites

 

[1] K000135946: BIG-IP PEM vulnerability CVE-2024-23982

https://my.f5.com/manage/s/article/K000135946

[2] K000137270: BIG-IP Advanced WAF and BIG-IP ASM and vulnerability CVE-2024-21789

https://my.f5.com/manage/s/article/K000137270

[3] K000137521: BIG-IP AFM vulnerability CVE-2024-21763

https://my.f5.com/manage/s/article/K000137521

[4] K000137334: F5 Application Visibility and Reporting module and BIG-IP Advanced WAF/ASM vulnerability CVE-2024-23805

https://my.f5.com/manage/s/article/K000137334

[5] K000137333: BIG-IP TMM vulnerability CVE-2024-24775

https://my.f5.com/manage/s/article/K000137333

[6] K000137675: BIG-IP HTTP/2 vulnerability CVE-2024-23314

https://my.f5.com/manage/s/article/K000137675

[7] K000138445: NGINX HTTP/3 QUIC vulnerability CVE-2024-24990

https://my.f5.com/manage/s/article/K000138445

[8] K000138444: NGINX HTTP/3 QUIC vulnerability CVE-2024-24989

https://my.f5.com/manage/s/article/K000138444

[9] K000137522: BIG-IP iControl REST vulnerability CVE-2024-22093

https://my.f5.com/manage/s/article/K000137522

[10] K000137416: BIG-IP Advanced WAF and BIG-IP ASM vulnerability CVE-2024-23308

https://my.f5.com/manage/s/article/K000137416

[11] K000134516: BIG-IP SSL Client Certificate LDAP and CRLDP Authentication profiles vulnerability CVE-2024-23979

https://my.f5.com/manage/s/article/K000134516

[12] K000135873: BIG-IP Websockets vulnerability CVE-2024-21849

https://my.f5.com/manage/s/article/K000135873

[13] K000137595: BIG-IP AFM signature matching vulnerability CVE-2024-21771

https://my.f5.com/manage/s/article/K000137595

[14] K32544615: BIG-IP iControl REST API vulnerability CVE-2024-22389

https://my.f5.com/manage/s/article/K32544615