Lucene search

K
cvelistF5CVELIST:CVE-2022-41624
HistoryOct 19, 2022 - 9:19 p.m.

CVE-2022-41624 BIG-IP iRules vulnerability CVE-2022-41624

2022-10-1921:19:24
CWE-401
f5
www.cve.org
6
big-ip
irules
memory resource
vulnerability
versions
sideband
traffic
virtual server

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

38.4%

In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.2, 15.1.x before 15.1.7, 14.1.x before 14.1.5.2, and 13.1.x before 13.1.5.1, when a sideband iRule is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization.

CNA Affected

[
  {
    "vendor": "F5",
    "product": "BIG-IP",
    "versions": [
      {
        "version": "17.0.x",
        "status": "affected",
        "lessThan": "17.0.0.1",
        "versionType": "custom"
      },
      {
        "version": "16.1.x",
        "status": "affected",
        "lessThan": "16.1.3.2",
        "versionType": "custom"
      },
      {
        "version": "15.1.x",
        "status": "affected",
        "lessThan": "15.1.7",
        "versionType": "custom"
      },
      {
        "version": "14.1.x",
        "status": "affected",
        "lessThan": "14.1.5.2",
        "versionType": "custom"
      },
      {
        "version": "13.1.x",
        "status": "affected",
        "lessThan": "13.1.5.1",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

38.4%

Related for CVELIST:CVE-2022-41624