CVE-2022-34844

Severity
7.5HIGH
EPSS
0.5%
top 35.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 4
Latest updateAug 5

Description

In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP or BIG-IQ on Amazon Web Services (AWS) systems, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Successful exploitation relies on conditions outside of the attacker's control. Note: Software versions which have reached End of Technical Support (EoTS) are not ev

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages14 packages

NVDf5/big-ip_local_traffic_manager15.1.015.1.6.1+1
NVDf5/big-ip_global_traffic_manager15.1.015.1.6.1+1
NVDf5/big-ip_link_controller15.1.015.1.6.1+1
CVEListV5f5/big-iq_centralized_management8.0.08.x*

🔴Vulnerability Details

2
GHSA
GHSA-8fg9-gw5f-85rh: In BIG-IP Versions 162022-08-05
CVEList
BIG-IP and BIG-IQ AWS vulnerability CVE-2022-348442022-08-04

📋Vendor Advisories

1
F5
CVE-2022-34844: In BIG-IP Versions 162022-08-04
CVE-2022-34844 (HIGH CVSS 7.5) | In BIG-IP Versions 16.1.x before 16 | cvebase.io