Lucene search

K
f5F5F5:K56412001
HistoryJan 09, 2023 - 12:00 a.m.

K56412001 : BIG-IP SSL OCSP Authentication profile vulnerability CVE-2023-22323

2023-01-0900:00:00
my.f5.com
13
big-ip
ssl
ocsp
authentication
vulnerability
cve-2023-22323
system performance
degradation
denial-of-service
data plane

AI Score

7

Confidence

High

EPSS

0.001

Percentile

39.0%

Security Advisory Description

When OCSP authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization. (CVE-2023-22323)

Impact

System performance can degrade until the Traffic Management Microkernel (TMM) process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only.

AI Score

7

Confidence

High

EPSS

0.001

Percentile

39.0%