CVE-2022-23019: Input Validation
On BIG-IP version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a message routing type virtual server is configured with both Diameter Session and Router Profiles, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23019?
CVE-2022-23019 has been classified with a high severity rating due to its potential to cause an increase in memory resource utilization.
How do I fix CVE-2022-23019?
To fix CVE-2022-23019, you should upgrade your F5 BIG-IP to the latest version that is not affected, specifically versions 16.1.2 or later for the 16.1.x series, 15.1.4.1 or later for the 15.1.x series, 14.1.4.4 or later for the 14.1.x series, and any versions less than 12.1.6 for the 12.1.x series.
Which software versions are affected by CVE-2022-23019?
Affected software versions for CVE-2022-23019 include F5 BIG-IP Access Policy Manager, Advanced Firewall Manager, Analytics, Application Acceleration Manager, Application Security Manager, and others across multiple versions as specified.
What are the potential impacts of CVE-2022-23019 on my system?
The potential impacts of CVE-2022-23019 include increased memory resource utilization which could lead to performance degradation or service disruption.
Is there a workaround for CVE-2022-23019?
Currently, no specific workaround for CVE-2022-23019 has been mentioned, making it essential to upgrade to a non-vulnerable version.