CVE-2022-23024 Information

Description

On BIG-IP AFM version 16.x before 16.1.0 15.1.x before 15.1.4.1 14.1.x before 14.1.4.2 and all versions of 13.1.x when the IPsec application layer gateway (ALG) logging profile is configured on an IPsec ALG virtual server undisclosed IPsec traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Reference

https://support.f5.com/csp/article/K54892865

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

7.5

Share on: