BIG-IP and BIG-IQ mcpd vulnerability CVE-2022-41694
CVE-2022-41694
4.9MEDIUM
Summary
In BIG-IP versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, and BIG-IQ versions 8.x before 8.2.0.1 and all versions of 7.x, when an SSL key is imported on a BIG-IP or BIG-IQ system, undisclosed input can cause MCPD to terminate.
Affected Version(s)
BIG-IP 16.1.x < 16.1.3
BIG-IP 15.1.x < 15.1.6.1
BIG-IP 14.1.x < 14.1.5
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered internally by F5.