cbcvebase.
CVE-2022-41813
published 2022-10-19

CVE-2022-41813: In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when BIG-IP is provisioned with PEM or AFM…

medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when BIG-IP is provisioned with PEM or AFM module, an undisclosed input can cause Traffic Management Microkernel (TMM) to terminate.

Affected

14 ranges
VendorProductVersion rangeFixed in
f5big-ip_advanced_firewall_manager13.1.0 – 13.1.5
f5big-ip_advanced_firewall_manager>= 14.1.0 < 14.1.514.1.5
f5big-ip_advanced_firewall_manager>= 15.1.0 < 15.1.6.115.1.6.1
f5big-ip_advanced_firewall_manager>= 16.1.0 < 16.1.3.116.1.3.1
f5big-ip_afm
f5big-ip_afm_pem>= 13.1.0 < 13.1.x*13.1.x*
f5big-ip_afm_pem>= 14.1.x < 14.1.514.1.5
f5big-ip_afm_pem>= 15.1.x < 15.1.6.115.1.6.1
f5big-ip_afm_pem>= 16.1.x < 16.1.3.116.1.3.1
f5big-ip_pem
f5big-ip_policy_enforcement_manager13.1.0 – 13.1.5
f5big-ip_policy_enforcement_manager>= 14.1.0 < 14.1.514.1.5
f5big-ip_policy_enforcement_manager>= 15.1.0 < 15.1.6.115.1.6.1
f5big-ip_policy_enforcement_manager>= 16.1.0 < 16.1.3.116.1.3.1