QID 377684
QID 377684: F5 BIG-IP Application Security Manager (ASM) Big-ip advanced Web Application Firewall (WAF) and Application Security Manager (ASM) bd vulnerability cve-2022-41836 (K47204506)
When an "Attack Signature False Positive Mode" enabled security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.CVE-2022-41836
Vulnerable Component: BIG-IP ASM
Affected Versions:
17.0.0
16.1.0 - 16.1.3
15.1.0 - 15.1.6
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
Traffic is disrupted while the bd process restarts. This vulnerability allows a remote unauthenticated attacker to cause a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only.
Solution
For more information about patch details please refer to K47204506
Vendor References
- K47204506 -
support.f5.com/csp/article/K47204506
CVEs related to QID 377684
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K47204506 |
|