CVE-2022-34862
04.08.2022, 18:15
In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when an LTM virtual server is configured to perform normalization, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| f5 | big-ip_access_policy_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
| f5 | big-ip_access_policy_manager | 14.1.0 ≤ 𝑥 < 14.1.5 |
| f5 | big-ip_access_policy_manager | 15.1.0 ≤ 𝑥 < 15.1.6.1 |
| f5 | big-ip_access_policy_manager | 16.1.0 ≤ 𝑥 < 16.1.3.1 |
| f5 | big-ip_advanced_firewall_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
| f5 | big-ip_advanced_firewall_manager | 14.1.0 ≤ 𝑥 < 14.1.5 |
| f5 | big-ip_advanced_firewall_manager | 15.1.0 ≤ 𝑥 < 15.1.6.1 |
| f5 | big-ip_advanced_firewall_manager | 16.1.0 ≤ 𝑥 < 16.1.3.1 |
| f5 | big-ip_analytics | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
| f5 | big-ip_analytics | 14.1.0 ≤ 𝑥 < 14.1.5 |
| f5 | big-ip_analytics | 15.1.0 ≤ 𝑥 < 15.1.6.1 |
| f5 | big-ip_analytics | 16.1.0 ≤ 𝑥 < 16.1.3.1 |
| f5 | big-ip_application_acceleration_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
| f5 | big-ip_application_acceleration_manager | 14.1.0 ≤ 𝑥 < 14.1.5 |
| f5 | big-ip_application_acceleration_manager | 15.1.0 ≤ 𝑥 < 15.1.6.1 |
| f5 | big-ip_application_acceleration_manager | 16.1.0 ≤ 𝑥 < 16.1.3.1 |
| f5 | big-ip_application_security_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
| f5 | big-ip_application_security_manager | 14.1.0 ≤ 𝑥 < 14.1.5 |
| f5 | big-ip_application_security_manager | 15.1.0 ≤ 𝑥 < 15.1.6.1 |
| f5 | big-ip_application_security_manager | 16.1.0 ≤ 𝑥 < 16.1.3.1 |
| f5 | big-ip_domain_name_system | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
| f5 | big-ip_domain_name_system | 14.1.0 ≤ 𝑥 < 14.1.5 |
| f5 | big-ip_domain_name_system | 15.1.0 ≤ 𝑥 < 15.1.6.1 |
| f5 | big-ip_domain_name_system | 16.1.0 ≤ 𝑥 < 16.1.3.1 |
| f5 | big-ip_fraud_protection_service | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
| f5 | big-ip_fraud_protection_service | 14.1.0 ≤ 𝑥 < 14.1.5 |
| f5 | big-ip_fraud_protection_service | 15.1.0 ≤ 𝑥 < 15.1.6.1 |
| f5 | big-ip_fraud_protection_service | 16.1.0 ≤ 𝑥 < 16.1.3.1 |
| f5 | big-ip_global_traffic_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
| f5 | big-ip_global_traffic_manager | 14.1.0 ≤ 𝑥 < 14.1.5 |
| f5 | big-ip_global_traffic_manager | 15.1.0 ≤ 𝑥 < 15.1.6.1 |
| f5 | big-ip_global_traffic_manager | 16.1.0 ≤ 𝑥 < 16.1.3.1 |
| f5 | big-ip_link_controller | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
| f5 | big-ip_link_controller | 14.1.0 ≤ 𝑥 < 14.1.5 |
| f5 | big-ip_link_controller | 15.1.0 ≤ 𝑥 < 15.1.6.1 |
| f5 | big-ip_link_controller | 16.1.0 ≤ 𝑥 < 16.1.3.1 |
| f5 | big-ip_local_traffic_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
| f5 | big-ip_local_traffic_manager | 14.1.0 ≤ 𝑥 < 14.1.5 |
| f5 | big-ip_local_traffic_manager | 15.1.0 ≤ 𝑥 < 15.1.6.1 |
| f5 | big-ip_local_traffic_manager | 16.1.0 ≤ 𝑥 < 16.1.3.1 |
| f5 | big-ip_policy_enforcement_manager | 13.1.0 ≤ 𝑥 ≤ 13.1.5 |
| f5 | big-ip_policy_enforcement_manager | 14.1.0 ≤ 𝑥 < 14.1.5 |
| f5 | big-ip_policy_enforcement_manager | 15.1.0 ≤ 𝑥 < 15.1.6.1 |
| f5 | big-ip_policy_enforcement_manager | 16.1.0 ≤ 𝑥 < 16.1.3.1 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| f5 | big-ip | 14.1.0 ≤ 𝑥 < 14.1.5 | CNA |
| f5 | big-ip | 15.1.0 ≤ 𝑥 < 15.1.6.1 | CNA |
| f5 | big-ip | 16.1.0 ≤ 𝑥 < 16.1.3.1 | CNA |
Common Weakness Enumeration