CVE-2022-23017: Null Pointer Dereference
On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when a virtual server is configured with a DNS profile with the Rapid Response Mode setting enabled and is configured on a BIG-IP system, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23017?
The severity of CVE-2022-23017 is rated as high due to the potential for denial of service.
How do I fix CVE-2022-23017?
To fix CVE-2022-23017, you should upgrade to the latest supported version of BIG-IP that is not vulnerable.
Which versions are affected by CVE-2022-23017?
CVE-2022-23017 affects BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x.
What type of vulnerability is CVE-2022-23017?
CVE-2022-23017 is a denial of service vulnerability associated with the DNS profile settings in BIG-IP systems.
What product categories are impacted by CVE-2022-23017?
CVE-2022-23017 impacts several F5 BIG-IP product categories, including Access Policy Manager, Advanced Firewall Manager, and Application Security Manager.