CVE-2023-3470

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Aug 2, 2023
Updated: Oct 13, 2023
CWE ID 287
CWE ID 1391

Summary

CVE-2023-3470 is a vulnerability affecting specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards. These systems generate deterministic passwords for the Crypto User account, making it predictable and susceptible to unauthorized access. An authenticated user with TMSH access to the BIG-IP system or anyone with physical access to the FIPS HSM can exploit this issue. Affected hardware includes 10350v-F, i5820-DF, i7820-DF, i15820-DF, 5250v-F, 7200v-F, 10200v-F, 6900-F, 8900-F, 11000-F, and 11050-F. Notably, vCMP systems allow all guests to share the same deterministic password, increasing the risk for multiple systems. This vulnerability does not affect the BIG-IP rSeries r5920-DF and r10920-DF, software FIPS implementations, or network HSM configurations. End-of-Technical-Support (EoTS) software versions were not evaluated.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share