CVE Vulnerabilities

CVE-2022-23018

Improper Handling of Exceptional Conditions

Published: Jan 25, 2022 | Modified: Feb 01, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.1 HIGH
AV:N/AC:M/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu

On BIG-IP AFM version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and 13.1.x beginning in 13.1.3.4, when a virtual server is configured with both HTTP protocol security and HTTP Proxy Connect profiles, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

Name Vendor Start Version End Version
Big-ip_advanced_firewall_manager F5 13.1.3.4 (including) 13.1.4.1 (excluding)
Big-ip_advanced_firewall_manager F5 14.1.0 (including) 14.1.4.5 (excluding)
Big-ip_advanced_firewall_manager F5 15.1.0 (including) 15.1.4.1 (excluding)
Big-ip_advanced_firewall_manager F5 16.1.0 (including) 16.1.2 (excluding)

References