CVE-2023-3470
6.1
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 0.9 / Impact: 5.2
Source: NVD
Description
Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account. The predictable nature of the password allows an authenticated user with TMSH access to the BIG-IP system, or anyone with physical access to the FIPS HSM, the information required to generate the correct password. On vCMP systems, all Guests share the same deterministic password, allowing those with TMSH access on one Guest to access keys of a different Guest.
The following BIG-IP hardware platforms are affected: 10350v-F, i5820-DF, i7820-DF, i15820-DF, 5250v-F, 7200v-F, 10200v-F, 6900-F, 8900-F, 11000-F, and 11050-F.
The BIG-IP rSeries r5920-DF and r10920-DF are not affected, nor does the issue affect software FIPS implementations or network HSM configurations.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected (68)
Products: F5: Big Ip Access Policy Manager, Big Ip Advanced Firewall Manager, Big Ip Advanced Web Application Firewall, Big Ip Analytics, Big Ip Application Acceleration Manager, Big Ip Application Security Manager, Big Ip Application Visibility And Reporting, Big Ip Carrier Grade Nat, Big Ip Ddos Hybrid Defender, Big Ip Domain Name System, Big Ip Edge Gateway, Big Ip Fraud Protection Service, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Local Traffic Manager, Big Ip Policy Enforcement Manager, Big Ip Ssl Orchestrator, Big Ip Webaccelerator, Big Ip Websafe, Big Ip 10350v F Firmware, Big Ip I5820 Df Firmware, Big Ip I7820 Df Firmware, Big Ip I15820 Df Firmware, Big Ip 5250v F Firmware, Big Ip 7200v F Firmware, Big Ip 10200v F Firmware, Big Ip 6900 F Firmware, Big Ip 8900 F Firmware, Big Ip 11000 F Firmware, Big Ip 11050 F Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 13.1.0 to 13.1.4 | |
| From 13.1.0 to 13.1.4 | |
| From 13.1.0 to 13.1.4 | |
| From 13.1.0 to 13.1.4 | |
| From 13.1.0 to 13.1.4 | |
| From 13.1.0 to 13.1.4 | |
| From 13.1.0 to 13.1.4 | |
| From 13.1.0 to 13.1.4 | |
| From 13.1.0 to 13.1.4 | |
| From 13.1.0 to 13.1.4 | |
| From 13.1.0 to 13.1.4 | |
| From 13.1.0 to 13.1.4 | |
| From 13.1.0 to 13.1.4 | |
| From 13.1.0 to 13.1.4 | |
| From 13.1.0 to 13.1.4 | |
| From 13.1.0 to 13.1.4 | |
| From 13.1.0 to 13.1.4 | |
| From 13.1.0 to 13.1.4 | |
| From 13.1.0 to 13.1.4 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
F5 Big Ip 10350v F | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
F5 Big Ip I5820 Df | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
F5 Big Ip I7820 Df | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
F5 Big Ip I15820 Df | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
F5 Big Ip 5250v F | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
F5 Big Ip 7200v F | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
F5 Big Ip 10200v F | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
F5 Big Ip 6900 F | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
F5 Big Ip 8900 F | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
F5 Big Ip 11000 F | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
F5 Big Ip 11050 F | All versions |
Related CWEs
CWE-1391
Use of Weak Credentials
The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.
CWE-287
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.