CVE-2022-41694

Severity
4.9MEDIUM
EPSS
0.7%
top 29.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 19
Latest updateOct 20

Description

In BIG-IP versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, and BIG-IQ versions 8.x before 8.2.0.1 and all versions of 7.x, when an SSL key is imported on a BIG-IP or BIG-IQ system, undisclosed input can cause MCPD to terminate.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 1.2 | Impact: 3.6

Affected Packages13 packages

NVDf5/big-ip_domain_name_system14.1.014.1.5+3
CVEListV5f5/big-ip16.1.x16.1.3+3
CVEListV5f5/big-iq8.x8.2.0.1+1
NVDf5/big-ip_analytics14.1.014.1.5+3
NVDf5/big-ip_link_controller14.1.014.1.5+3

🔴Vulnerability Details

2
GHSA
GHSA-pvwc-79jh-rc76: In BIG-IP versions 162022-10-20
CVEList
BIG-IP and BIG-IQ mcpd vulnerability CVE-2022-416942022-10-19

📋Vendor Advisories

1
F5
CVE-2022-41694: In BIG-IP versions 162022-10-19