QID 377985

Date Published: 2023-03-29

QID 377985: F5 BIG-IP HTTP/2 Profile Vulnerability CVE-2023-22664 (K56676554)

BIG-IP has released a security update for BIG-IP to fix the vulnerabilities.

Vulnerable Component:
Affected Versions:
17.0.0
16.1.0 - 16.1.3

QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.

This vulnerability allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the BIG-IP system

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Low - 0 severity.
  • Solution
    Please refer to K56676554 for more information.
    Vendor References

    CVEs related to QID 377985

    Software Advisories
    Advisory ID Software Component Link
    K56676554 URL Logo my.f5.com/manage/s/article/K56676554