CVE Vulnerabilities

CVE-2022-23018

Improper Handling of Exceptional Conditions

Published: Jan 25, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.1 HIGH
AV:N/AC:M/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

On BIG-IP AFM version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and 13.1.x beginning in 13.1.3.4, when a virtual server is configured with both HTTP protocol security and HTTP Proxy Connect profiles, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

NameVendorStart VersionEnd Version
Big-ip_advanced_firewall_managerF513.1.3.4 (including)13.1.4.1 (excluding)
Big-ip_advanced_firewall_managerF514.1.0 (including)14.1.4.5 (excluding)
Big-ip_advanced_firewall_managerF515.1.0 (including)15.1.4.1 (excluding)
Big-ip_advanced_firewall_managerF516.1.0 (including)16.1.2 (excluding)

References