CVE-2022-23025
Published Jan 25, 2022
Last updated 3 years ago
Overview
- Description
- On BIG-IP version 16.1.x before 16.1.1, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, when a SIP ALG profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- Source
- f5sirt@f5.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:N/A:P
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "50288008-B90F-4882-80AD-2C70A1F1E2DD", "versionEndIncluding": "13.1.4", "versionStartIncluding": "13.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D5286F92-3E35-4B00-AA8F-AC96449BD2F6", "versionEndIncluding": "14.1.4", "versionStartIncluding": "14.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FE0AA66D-D6EF-4D7E-B975-9CF1A19AF279", "versionEndIncluding": "15.1.3", "versionStartIncluding": "15.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A0EF18CE-C9E3-4049-ABB3-72D34EC3BEA8", "versionEndIncluding": "16.1.1", "versionStartIncluding": "16.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C37ABF73-E093-498B-99F3-11D5A3908C7F", "versionEndIncluding": "13.1.4", "versionStartIncluding": "13.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB20EE99-82A2-4FF9-B1C5-A0E40816AA5A", "versionEndIncluding": "14.1.4", "versionStartIncluding": "14.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7C23AD78-B214-48C7-996C-F3BD2DE30B3B", "versionEndIncluding": "15.1.3", "versionStartIncluding": "15.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F9481EEC-265F-4618-88EE-6F55286E050B", "versionEndIncluding": "16.1.1", "versionStartIncluding": "16.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D4C23715-2E2A-4FC6-8303-007AA2355779", "versionEndIncluding": "13.1.4", "versionStartIncluding": "13.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D2A1BB14-BEB5-43DD-878D-83E51FBFD4E0", "versionEndIncluding": "14.1.4", "versionStartIncluding": "14.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "56D19CAF-676D-4029-91C4-80140C4C4416", "versionEndIncluding": "15.1.3", "versionStartIncluding": "15.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4CDF2944-86BE-4625-A0E2-E6EA6B24CF2D", "versionEndIncluding": "16.1.1", "versionStartIncluding": "16.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "18F2AC19-1085-48C3-B270-DD3E17A7870D", "versionEndIncluding": "13.1.4", "versionStartIncluding": "13.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6CCAB1F6-9AD7-4743-A6B6-D42567427845", "versionEndIncluding": "14.1.4", "versionStartIncluding": "14.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "51E8CE17-224C-45C8-845D-32A90559F35C", "versionEndIncluding": "15.1.3", "versionStartIncluding": "15.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1CB5FDAC-0C23-4A36-8C3B-DE751E86F5E6", "versionEndIncluding": "16.1.1", "versionStartIncluding": "16.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EDDC86D0-B9D6-42AE-959E-CC40C6F275EE", "versionEndIncluding": "13.1.4", "versionStartIncluding": "13.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6B90B84E-0BAA-465E-A4D3-20902772B951", "versionEndIncluding": "14.1.4", "versionStartIncluding": "14.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9C7C7515-D182-40C6-9224-B0C9A92F94BB", "versionEndIncluding": "15.1.3", "versionStartIncluding": "15.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6010929B-1BE5-460C-9649-BB97F2EEF0A5", "versionEndIncluding": "16.1.1", "versionStartIncluding": "16.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D17DCE22-99F8-422C-A414-86CFA78BA425", "versionEndIncluding": "13.1.4", "versionStartIncluding": "13.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "15EB0439-9C16-45C2-895D-44D6ED1A028A", "versionEndIncluding": "14.1.4", "versionStartIncluding": "14.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2408EED7-CFDF-414C-82DB-FA9541DE2138", "versionEndIncluding": "15.1.3", "versionStartIncluding": "15.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6A7DAE74-52A3-43B7-90FA-E3009007FA37", "versionEndIncluding": "16.1.1", "versionStartIncluding": "16.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B2315AF-62CA-4948-AF3A-CC2D08F63BEF", "versionEndIncluding": "13.1.4", "versionStartIncluding": "13.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EF0981E9-9826-4D59-9FF1-709208A88B0C", "versionEndIncluding": "14.1.4", "versionStartIncluding": "14.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A062EB3-9A75-4D74-B9F8-AE27F401C2CD", "versionEndIncluding": "15.1.3", "versionStartIncluding": "15.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EAC4BB37-518D-4612-8BE8-B784FC13DBD7", "versionEndIncluding": "16.1.1", "versionStartIncluding": "16.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F82E9A35-A3E2-4915-BE23-B321C18BE6C3", "versionEndIncluding": "13.1.4", "versionStartIncluding": "13.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A27C0FAB-2C2F-4F5E-8EF4-CC4923B848F4", "versionEndIncluding": "14.1.4", "versionStartIncluding": "14.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D3EB0C5A-FC0E-46A6-A59A-01B2091E8C84", "versionEndIncluding": "15.1.3", "versionStartIncluding": "15.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "49FEB42F-B9F4-4AE5-A503-A21930F60C1B", "versionEndIncluding": "16.1.1", "versionStartIncluding": "16.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6B486BC4-2258-42FC-834E-22958ACFCA13", "versionEndIncluding": "13.1.4", "versionStartIncluding": "13.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DFD7DB4C-6CA7-4C26-81AB-1F9A27F4355A", "versionEndIncluding": "14.1.4", "versionStartIncluding": "14.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C956EAAD-0750-4E25-9A69-8B1DD156B6BE", "versionEndIncluding": "15.1.3", "versionStartIncluding": "15.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F2287CB0-6423-4DD1-8A48-B0C624F220E8", "versionEndIncluding": "16.1.1", "versionStartIncluding": "16.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3FCEA7BA-FBAB-4D94-86D9-51B7F8E4C0A1", "versionEndIncluding": "13.1.4", "versionStartIncluding": "13.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FC486854-8119-4DDC-BE29-AB3394D2A214", "versionEndIncluding": "14.1.4", "versionStartIncluding": "14.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "30EEE0A7-D601-43A5-80A7-44D637D6847F", "versionEndIncluding": "15.1.3", "versionStartIncluding": "15.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F46C74F5-66DA-4B50-B0EF-80326C2D13AD", "versionEndIncluding": "16.1.1", "versionStartIncluding": "16.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ADE1E0A6-DE70-4D46-B493-671E23EEA32D", "versionEndIncluding": "13.1.4", "versionStartIncluding": "13.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C5FF402E-8A6B-498F-BDB3-089EFAE55061", "versionEndIncluding": "14.1.4", "versionStartIncluding": "14.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A3D935FC-8637-44B1-B836-EBDA4AB22961", "versionEndIncluding": "15.1.3", "versionStartIncluding": "15.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BC9945CF-2C6F-46D5-BC7C-59C3D4AEB4B8", "versionEndIncluding": "16.1.1", "versionStartIncluding": "16.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "228F7E70-F93D-40BD-9C33-2A51CB6B931F", "versionEndIncluding": "13.1.4", "versionStartIncluding": "13.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D38D907A-2071-4675-8616-733E3C96C95B", "versionEndIncluding": "14.1.4", "versionStartIncluding": "14.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "55AE6626-80D5-4B90-B579-34D3EB34EF3C", "versionEndIncluding": "15.1.3", "versionStartIncluding": "15.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B64336FE-BC6B-4303-B745-4C909D39BAE3", "versionEndIncluding": "16.1.1", "versionStartIncluding": "16.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F4574B7D-DFAF-4527-8E19-2E37650A1494", "versionEndIncluding": "13.1.4", "versionStartIncluding": "13.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "30382C56-3299-4D9C-943B-46B8CECB31BF", "versionEndIncluding": "14.1.4", "versionStartIncluding": "14.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "265F5361-DC0B-4AB2-ACD3-6F32680881C2", "versionEndIncluding": "15.1.3", "versionStartIncluding": "15.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9F85ED96-4BA9-4377-A0EC-D338D6B7245B", "versionEndIncluding": "16.1.1", "versionStartIncluding": "16.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5D2210B0-898F-49A9-ABEC-55971978C2AA", "versionEndIncluding": "13.1.4", "versionStartIncluding": "13.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0C4A0BD4-F4CE-43BD-A957-3812DD1DCE92", "versionEndIncluding": "14.1.4", "versionStartIncluding": "14.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2E573320-1B7B-462F-8447-113C5CDE7472", "versionEndIncluding": "15.1.3", "versionStartIncluding": "15.1.0" }, { "criteria": "cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9E4382E1-13DC-4F55-AB46-9F9F4AE8BFD5", "versionEndIncluding": "16.1.1", "versionStartIncluding": "16.1.0" } ], "operator": "OR" } ] } ]