QID 378102
Date Published: 2023-03-22
QID 378102: F5 BIG-IP Hypertext Transfer Protocol (HTTP) Profile Vulnerability CVE-2023-22302 (K58550078)
When an HTTP profile is configured on a virtual server and conditions beyond the attackers control exist on the target pool member, undisclosed requests sent to the BIG-IP system can cause the Traffic Management Microkernel to terminate .
Vulnerable Component: BIG-IP All Modules
Affected Versions:
17.0.0
16.1.2.2 - 16.1.3
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
Traffic is disrupted while the TMM Process restarts. This vulnerability allows a remote unauthenticated attacker to cause a Denial of Service on BIG-IP system. There is no control plane exposure ; this is a data plane issue only.
Solution
The vendor has released patch, for more information please visit: K58550078
Vendor References
- K58550078 -
my.f5.com/manage/s/article/K58550078
CVEs related to QID 378102
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K58550078 |
|