CVE-2022-23024
published 2022-01-25CVE-2022-23024: On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.2, and all versions of 13.1.x, when the IPsec application layer gateway…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.90%
55.7th percentile
On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.2, and all versions of 13.1.x, when the IPsec application layer gateway (ALG) logging profile is configured on an IPsec ALG virtual server, undisclosed IPsec traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_advanced_firewall_manager | 13.1.0 – 13.1.4 | — |
| f5 | big-ip_advanced_firewall_manager | 14.1.0 – 14.1.4.1 | — |
| f5 | big-ip_advanced_firewall_manager | 15.1.0 – 15.1.4 | — |
| f5 | big-ip_afm | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2022-23024: On BIG-IP AFM version 16
vendor_f5·2022-01-25·CVSS 7.5
CVE-2022-23024 [HIGH] CWE-400 CVE-2022-23024: On BIG-IP AFM version 16
CVE-2022-23024: On BIG-IP AFM version 16
On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.2, and all versions of 13.1.x, when the IPsec application layer gateway (ALG) logging profile is configured on an IPsec ALG virtual server, undisclosed IPsec traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: BIG-IP AFM
Affected Versions: 13.1.0 - 13.1.4; 14.1.0 - 14.1.4.1; 15.1.0 - 15.1.4
F5 Advisory Articles: K54892865
F5 References: https://support.f5.com/csp/article/K54892865
GHSA
GHSA-q727-99h7-2wcw: On BIG-IP AFM version 16
ghsa_unreviewed·2022-01-26
CVE-2022-23024 [HIGH] CWE-400 GHSA-q727-99h7-2wcw: On BIG-IP AFM version 16
On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.2, and all versions of 13.1.x, when the IPsec application layer gateway (ALG) logging profile is configured on an IPsec ALG virtual server, undisclosed IPsec traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-01-25
Published