SYN Cookie Protection Issue in BIG-IP AFM by F5 Networks
CVE-2022-23028
5.3MEDIUM
Summary
An issue exists in the BIG-IP AFM related to TCP Half Open flood vector when global SYN cookie protection is enabled. This causes certain types of TCP connections to fail, impacting the availability and reliability of services. It affects multiple versions of the BIG-IP AFM, necessitating attention from network administrators to ensure proper handling of TCP connections under flood attack conditions.
Affected Version(s)
BIG-IP AFM 16.x before 16.1.0, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved