CVE-2023-22839

On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled, undisclosed requests cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
f5CNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
VendorProductVersion
f5big-ip_domain_name_system
13.1.0 ≤
𝑥
≤ 13.1.5
f5big-ip_domain_name_system
14.1.0 ≤
𝑥
< 14.1.5.3
f5big-ip_domain_name_system
15.1.0 ≤
𝑥
< 15.1.7
f5big-ip_domain_name_system
16.1.0 ≤
𝑥
< 16.1.3.3
f5big-ip_domain_name_system
17.0.0 ≤
𝑥
< 17.0.0.2
f5big-ip_local_traffic_manager
13.1.0 ≤
𝑥
≤ 13.1.5
f5big-ip_local_traffic_manager
14.1.0 ≤
𝑥
< 14.1.5.3
f5big-ip_local_traffic_manager
15.1.0 ≤
𝑥
< 15.1.7
f5big-ip_local_traffic_manager
16.1.0 ≤
𝑥
< 16.1.3.3
f5big-ip_local_traffic_manager
17.0.0 ≤
𝑥
< 17.0.0.2
f5big-ip_10000s_firmware
-
f5big-ip_10200v_firmware
-
f5big-ip_10200v-ssl_firmware
-
f5big-ip_12000_firmware
-
f5big-ip_5000s_firmware
-
f5big-ip_5200v_firmware
-
f5big-ip_5200v-ssl_firmware
-
f5big-ip_7000s_firmware
-
f5big-ip_7200v_firmware
-
f5big-ip_7200v-ssl_firmware
-
f5big-ip_i10600_firmware
-
f5big-ip_i10800_firmware
-
f5big-ip_i11600_firmware
-
f5big-ip_i11800_firmware
-
f5big-ip_i15600_firmware
-
f5big-ip_i15800_firmware
-
f5big-ip_i5600_firmware
-
f5big-ip_i5800_firmware
-
f5big-ip_i7600_firmware
-
f5big-ip_i7800_firmware
-
f5r10600_firmware
-
f5r10800_firmware
-
f5r10900_firmware
-
f5r5600_firmware
-
f5r5800_firmware
-
f5r5900_firmware
-
f5velos_bx110_firmware
-
f5viprion_b2100_firmware
-
f5viprion_b2150_firmware
-
f5viprion_b2250_firmware
-
f5viprion_b4300_firmware
-
f5viprion_b4450_firmware
-
𝑥
= Vulnerable software versions