QID 377681
QID 377681: F5 BIG-IP Big-ip Traffic Management Microkernel (TMM) vulnerability cve-2022-41983 (K31523465)
While Intel QAT (QuickAssist Technology) and the AES-GCM/CCM cipher is in use, undisclosed conditions cause the BIG-IP system to send data unencrypted, even with an SSL profile applied.CVE-2022-41983
Vulnerable Component: BIG-IP ASM,LTM,APM
Affected Versions:
16.1.0 - 16.1.3
15.1.0 - 15.1.6
14.1.0 - 14.1.5
13.1.0 - 13.1.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
This vulnerability may expose confidential information to a man-in-the-middle attacker, as data is sent without required encryption.
Solution
For more information about patch details please refer to K31523465
Vendor References
- K31523465 -
support.f5.com/csp/article/K31523465
CVEs related to QID 377681
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K31523465 |
|