CVE-2022-34862Infinite Loop in F5 Big-ip Global Traffic Manager

CWE-835Infinite Loop4 documents4 sources
Severity
7.5HIGHNVD
EPSS
1.0%
top 23.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 4
Latest updateAug 5

Description

In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when an LTM virtual server is configured to perform normalization, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages12 packages

NVDf5/big-ip_local_traffic_manager14.1.014.1.5+3
NVDf5/big-ip_global_traffic_manager14.1.014.1.5+3
CVEListV5f5/big-ip13.1.013.1.x*+3
NVDf5/big-ip_analytics14.1.014.1.5+3
NVDf5/big-ip_link_controller14.1.014.1.5+3

🔴Vulnerability Details

2
GHSA
GHSA-fjcc-47q7-fx2g: In BIG-IP Versions 162022-08-05
CVEList
TMM vulnerability CVE-2022-348622022-08-04

📋Vendor Advisories

1
F5
CVE-2022-34862: In BIG-IP Versions 162022-08-04
CVE-2022-34862 — Infinite Loop in F5 | cvebase