QID 378089
Date Published: 2023-03-22
QID 378089: F5 BIG-IP Virtual Edition Vulnerability (K24572686)
When FastL4 profile is configured on a virtual server in BIG-IP Virtual Edition, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. (CVE-2023-23555)
Vulnerable Component: BIG-IP (All Modules)
Affected Versions:
15.1.4 - 15.1.7
14.1.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
Traffic is disrupted while the TMM process restarts. This vulnerability allows a remote unauthenticated attacker to cause a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only.
Solution
Please refer to K24572686 for more information.
Vendor References
- K24572686 -
my.f5.com/manage/s/article/K24572686
CVEs related to QID 378089
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K24572686 |
|