QID 377674
QID 377674: F5 BIG-IP Application Security Manager (ASM) Big-ip advanced Web Application Firewall (WAF) and Application Security Manager (ASM) bd vulnerability cve-2022-41691 (K02694732)
When an F5 BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate. CVE-2022-41691
Vulnerable Component: BIG-IP ASM
Affected Versions:
14.1.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
Traffic is disrupted while the bd process restarts. This vulnerability allows a remote unauthenticated attacker to cause a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only.
Solution
For more information about patch details please refer to K02694732
Vendor References
- K02694732 -
support.f5.com/csp/article/K02694732
CVEs related to QID 377674
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K02694732 |
|