« Volver al listado

CVE-2023-39447

Estado: ModificadaMedia (4.4)—

When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-39447",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-39447",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-18T20:29:59.580695Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "f5sirt@f5.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "f5sirt@f5.com",
      "affectedData": [
        {
          "vendor": "F5",
          "modules": [
            "APM"
          ],
          "product": "BIG-IP",
          "versions": [
            {
              "status": "unaffected",
              "version": "17.1.0",
              "lessThan": "*",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "16.1.0",
              "lessThan": "16.1.4",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "15.1.0",
              "lessThan": "15.1.8",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "14.1.0",
              "lessThan": "*",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "13.1.0",
              "lessThan": "*",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "F5",
          "modules": [
            "Guided Configuration"
          ],
          "product": "BIG-IP",
          "versions": [
            {
              "status": "affected",
              "version": "6.0",
              "lessThan": "9.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2023-10-10T13:15:20.613",
  "references": [
    {
      "url": "https://my.f5.com/manage/s/article/K47756555",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "f5sirt@f5.com"
    },
    {
      "url": "https://my.f5.com/manage/s/article/K47756555",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "f5sirt@f5.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-532"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\nWhen BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log.  \n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.\n\n\n\n"
    },
    {
      "lang": "es",
      "value": "Cuando se configura BIG-IP APM Guided Configurations, es posible que se registre información confidencial no divulgada en restnoded log. Nota: Las versiones de software que han llegado al End of Technical Support (EoTS) no se evalúan."
    }
  ],
  "lastModified": "2026-06-17T06:12:21.210",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "48743FD4-1E72-4550-92D6-F06D6D0AF142",
              "versionEndExcluding": "15.1.8",
              "versionStartIncluding": "15.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8F16422-A642-4614-96F2-E5B4877E8206",
              "versionEndExcluding": "16.1.4",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:17.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AD637AF5-F7D1-428F-955E-16756B7476E0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_guided_configuration:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C36042F8-9B48-4E0D-ABC1-F10BE2A49CB8",
              "versionEndIncluding": "7.7",
              "versionStartIncluding": "7.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_guided_configuration:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63E1215D-2724-4249-B0FD-16C32480A11D"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_guided_configuration:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6AED33D2-594D-4057-A7D5-041665AA6E07"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "f5sirt@f5.com"
}