CVE-2022-23024: High severity f5 big-ip advanced firewall manager vulnerability
On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.2, and all versions of 13.1.x, when the IPsec application layer gateway (ALG) logging profile is configured on an IPsec ALG virtual server, undisclosed IPsec traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23024?
CVE-2022-23024 has a high severity rating, indicating that it may lead to significant security risks if exploited.
How do I fix CVE-2022-23024?
To fix CVE-2022-23024, upgrade to the latest version of F5 BIG-IP Advanced Firewall Manager that is not vulnerable.
What versions of F5 BIG-IP Advanced Firewall Manager are affected by CVE-2022-23024?
CVE-2022-23024 affects F5 BIG-IP Advanced Firewall Manager versions 13.1.x before 13.1.4, 14.1.x before 14.1.4.2, 15.1.x before 15.1.4.1, and 16.x before 16.1.0.
What type of attack does CVE-2022-23024 expose systems to?
CVE-2022-23024 can expose systems to potential denial-of-service attacks through undisclosed IPsec traffic.
Is there a workaround for CVE-2022-23024?
Currently, the best mitigation for CVE-2022-23024 is to upgrade the affected software to a secure version.