First published: Tue Jan 25 2022(Updated: )
On BIG-IP version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a message routing type virtual server is configured with both Diameter Session and Router Profiles, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Access Policy Manager | >=12.1.0<=12.1.6 | |
F5 Access Policy Manager | >=13.1.0<=13.1.4 | |
F5 Access Policy Manager | >=14.1.0<14.1.4.4 | |
F5 Access Policy Manager | >=15.1.0<15.1.4.1 | |
F5 Access Policy Manager | >=16.1.0<16.1.2 | |
F5 BIG-IP Advanced Firewall Manager | >=12.1.0<=12.1.6 | |
F5 BIG-IP Advanced Firewall Manager | >=13.1.0<=13.1.4 | |
F5 BIG-IP Advanced Firewall Manager | >=14.1.0<14.1.4.4 | |
F5 BIG-IP Advanced Firewall Manager | >=15.1.0<15.1.4.1 | |
F5 BIG-IP Advanced Firewall Manager | >=16.1.0<16.1.2 | |
F5 BIG-IP Analytics | >=12.1.0<=12.1.6 | |
F5 BIG-IP Analytics | >=13.1.0<=13.1.4 | |
F5 BIG-IP Analytics | >=14.1.0<14.1.4.4 | |
F5 BIG-IP Analytics | >=15.1.0<15.1.4.1 | |
F5 BIG-IP Analytics | >=16.1.0<16.1.2 | |
F5 BIG-IP Application Acceleration Manager | >=12.1.0<=12.1.6 | |
F5 BIG-IP Application Acceleration Manager | >=13.1.0<=13.1.4 | |
F5 BIG-IP Application Acceleration Manager | >=14.1.0<14.1.4.4 | |
F5 BIG-IP Application Acceleration Manager | >=15.1.0<15.1.4.1 | |
F5 BIG-IP Application Acceleration Manager | >=16.1.0<16.1.2 | |
F5 Application Security Manager | >=12.1.0<=12.1.6 | |
F5 Application Security Manager | >=13.1.0<=13.1.4 | |
F5 Application Security Manager | >=14.1.0<14.1.4.4 | |
F5 Application Security Manager | >=15.1.0<15.1.4.1 | |
F5 Application Security Manager | >=16.1.0<16.1.2 | |
F5 BIG-IP | >=12.1.0<=12.1.6 | |
F5 BIG-IP | >=13.1.0<=13.1.4 | |
F5 BIG-IP | >=14.1.0<14.1.4.4 | |
F5 BIG-IP | >=15.1.0<15.1.4.1 | |
F5 BIG-IP | >=16.1.0<=16.1.2 | |
F5 BIG-IP Fraud Protection Service | >=12.1.0<=12.1.6 | |
F5 BIG-IP Fraud Protection Service | >=13.1.0<=13.1.4 | |
F5 BIG-IP Fraud Protection Service | >=14.1.0<14.1.4.4 | |
F5 BIG-IP Fraud Protection Service | >=15.1.0<15.1.4.1 | |
F5 BIG-IP Fraud Protection Service | >=16.1.0<16.1.2 | |
Riverbed SteelApp Traffic Manager | >=12.1.0<=12.1.6 | |
Riverbed SteelApp Traffic Manager | >=13.1.0<=13.1.4 | |
Riverbed SteelApp Traffic Manager | >=14.1.0<14.1.4.4 | |
Riverbed SteelApp Traffic Manager | >=15.1.0<15.1.4.1 | |
Riverbed SteelApp Traffic Manager | >=16.1.0<=16.1.2 | |
F5 BIG-IP Link Controller | >=12.1.0<=12.1.6 | |
F5 BIG-IP Link Controller | >=13.1.0<=13.1.4 | |
F5 BIG-IP Link Controller | >=14.1.0<14.1.4.4 | |
F5 BIG-IP Link Controller | >=15.1.0<15.1.4.1 | |
F5 BIG-IP Link Controller | >=16.1.0<16.1.2 | |
Riverbed SteelApp Traffic Manager | >=12.1.0<=12.1.6 | |
Riverbed SteelApp Traffic Manager | >=13.1.0<=13.1.4 | |
Riverbed SteelApp Traffic Manager | >=14.1.0<14.1.4.4 | |
Riverbed SteelApp Traffic Manager | >=15.1.0<15.1.4.1 | |
Riverbed SteelApp Traffic Manager | >=16.1.0<16.1.2 | |
F5 BIG-IP Policy Enforcement Manager | >=12.1.0<=12.1.6 | |
F5 BIG-IP Policy Enforcement Manager | >=13.1.0<=13.1.4 | |
F5 BIG-IP Policy Enforcement Manager | >=14.1.0<14.1.4.4 | |
F5 BIG-IP Policy Enforcement Manager | >=15.1.0<15.1.4.1 | |
F5 BIG-IP Policy Enforcement Manager | >=16.1.0<16.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23019 has been classified with a high severity rating due to its potential to cause an increase in memory resource utilization.
To fix CVE-2022-23019, you should upgrade your F5 BIG-IP to the latest version that is not affected, specifically versions 16.1.2 or later for the 16.1.x series, 15.1.4.1 or later for the 15.1.x series, 14.1.4.4 or later for the 14.1.x series, and any versions less than 12.1.6 for the 12.1.x series.
Affected software versions for CVE-2022-23019 include F5 BIG-IP Access Policy Manager, Advanced Firewall Manager, Analytics, Application Acceleration Manager, Application Security Manager, and others across multiple versions as specified.
The potential impacts of CVE-2022-23019 include increased memory resource utilization which could lead to performance degradation or service disruption.
Currently, no specific workaround for CVE-2022-23019 has been mentioned, making it essential to upgrade to a non-vulnerable version.