A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appliance mode BIG-IP, a successful exploit of this vulnerability can allow the attacker to cross a security boundary.
This issue affects BIG-IP only (not BIG-IQ), and at the moment of publishing the current advisory, they are not yet patched. The currently supported versions known to be vulnerable are:
If any of the affected versions of this product exist on your infrastructure and since the official patch has not been published yet, kindly:
Make sure to follow F5’s security advisory to mitigate any possible attacks.
The Threat Hunting and SOC teams of OBRELA remain vigilant and continue to monitor the activity.
https://my.f5.com/manage/s/article/K000130415
https://www.rapid7.com/blog/post/2023/02/01/cve-2023-22374-f5-big-ip-format-string-vulnerability/