07-Feb-2023 01:04
Hi
Yesterday F5 published K56412001: BIG-IP SSL OCSP Authentication profile vulnerability CVE-2023-22323 has been published https://my.f5.com/manage/s/article/K56412001.
In the KB F5, mention the following in terms of vulnerability.
Currently, I am using 15.1.2.1-0.x.x. Am I vulnerable as F5 mentioned Branch 15.x and Versions known to be vulnerable is 15.1.0 - 15.1.8.
07-Feb-2023 01:51
15.1.2.1-0.x.x is within the vulnerable range.
You can also upload a qkview to ihealth and get all the known vulnerabilities for your specific version.
07-Feb-2023 01:56
I am very new to f5 BIG-IP in terms of using its features.
Can you please guide how to use ihealth for vulnerabilities? Is this free, or do I need to have the subscription?
07-Feb-2023 04:02
iHealth is free but requires registration.
Quick video overview of iHealth:
https://www.youtube.com/watch?v=UFg7_3-HL5A
Vulnerabilietes can be found in diagnostic tab.
07-Feb-2023 19:57
Thanks for the reply.
Thanks for the information on iHealth.
You told me that 15.1.2.1-0.x.x is within the vulnerable range. How may I know, according to K56412001: BIG-IP SSL OCSP Authentication profile vulnerability CVE-2023-22323 has been published https://my.f5.com/manage/s/article/K56412001.
07-Feb-2023 23:53 - edited 08-Feb-2023 01:57
Because in this case you consider your release to be 15.1.2 which is within the vulnerable range. Quoting from https://my.f5.com/manage/s/article/K51812227:
Versions known to be vulnerable: The range of product versions within each branch that are confirmed by F5 Product Development as vulnerable. Point releases and hotfixes are not listed in this column, unless a vulnerability is specifically introduced in a given point release or hotfix. Vulnerable versions include all point releases or hotfixes for a given software version. For example, if 13.1.0 is listed as vulnerable, then 13.1.0.1 and 13.1.0.2 are also considered vulnerable if neither of those point releases are listed in the Fixes introduced in column.
08-Feb-2023 05:32
Your mentioned URL https://my.f5.com/manage/s/article/K51812227 don't have 15.1.2. Maybe you pasted the wrong URL.
But in the case of the URL https://my.f5.com/manage/s/article/K56412001, is BIGIP-15.1.2.1-0.0.10 vulnerable?
08-Feb-2023 06:02
If you read the kb you mentioned entirely there's a link to the other kb which just explain how versioning works for security alerts
13-Feb-2023 21:05
15.1.2 is within the range of 15.1.0 - 15.1.8 (15.1.0, 15.1.1, 15.1.2, 15.1.3, etc to 15.1.8), so as @Amine_Kadimi mentioned, you are vulnerable. Thirding @Amine_Kadimi and @RadekR's recommendations to register and start using iHealth for easy checks!
09-Feb-2023 00:30
Thanks for helping me as well 🙂
13-Feb-2023 19:03
Thanks for the links.