CVE-2023-40534
published 2023-10-10CVE-2023-40534: When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the HTTP_REQUEST event or Local Traffic…
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the HTTP_REQUEST event or Local Traffic Policy are associated with the virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
62 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | >= 16.1.0 < 16.1.4.1.0.13.5-ENG | 16.1.4.1.0.13.5-ENG |
| f5 | big-ip | >= 17.1.0 < 17.1.0.3.0.23.4-ENG | 17.1.0.3.0.23.4-ENG |
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | >= 16.1.0 < 16.1.4.1 | 16.1.4.1 |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | >= 16.1.0 < 16.1.4.1 | 16.1.4.1 |
| f5 | big-ip_advanced_waf | — | — |
| f5 | big-ip_advanced_web_application_firewall | — | — |
| f5 | big-ip_advanced_web_application_firewall | >= 16.1.0 < 16.1.4.1 | 16.1.4.1 |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | >= 16.1.0 < 16.1.4.1 | 16.1.4.1 |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | >= 16.1.0 < 16.1.4.1 | 16.1.4.1 |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | >= 16.1.0 < 16.1.4.1 | 16.1.4.1 |
| f5 | big-ip_application_visibility_and_reporting | — | — |
| f5 | big-ip_application_visibility_and_reporting | >= 16.1.0 < 16.1.4.1 | 16.1.4.1 |
| f5 | big-ip_asm | — | — |
| f5 | big-ip_avr | — | — |
| f5 | big-ip_carrier-grade_nat | — | — |
| f5 | big-ip_carrier-grade_nat | >= 16.1.0 < 16.1.4.1 | 16.1.4.1 |