Denial of Service Vulnerability in F5 BIG-IP Components
CVE-2022-29491

7.5HIGH

Key Information:

Vendor
F5
Vendor
CVE Published:
5 May 2022

Summary

The vulnerability exists in F5 BIG-IP components configured with HTTP or TCP on one side and DTLS on the other, where certain undisclosed requests can lead to unexpected TMM process termination. This situation may result in service disruptions, affecting the overall availability of services running on affected F5 BIG-IP installations. Versions 16.1.x, 15.1.x, 14.1.x, and legacy versions are impacted, necessitating prompt attention to mitigate potential risks.

Affected Version(s)

BIG-IP LTM, Advanced WAF, ASM, and APM 13.1.x

BIG-IP LTM, Advanced WAF, ASM, and APM 12.1.x

BIG-IP LTM, Advanced WAF, ASM, and APM 11.6.x

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.