CVE-2022-23025: Null Pointer Dereference
On BIG-IP version 16.1.x before 16.1.1, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, when a SIP ALG profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23025?
CVE-2022-23025 has been assigned a high severity rating due to its potential to cause Traffic Management Microkernel (TMM) termination.
How do I fix CVE-2022-23025?
To mitigate CVE-2022-23025, it is recommended to upgrade to the latest fixed versions of BIG-IP, specifically version 16.1.1 or later, 15.1.4, or 14.1.4.4.
What are the affected versions for CVE-2022-23025?
CVE-2022-23025 affects BIG-IP versions 16.1.x before 16.1.1, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x.
Can CVE-2022-23025 be exploited remotely?
Yes, CVE-2022-23025 can potentially be exploited remotely when a SIP ALG profile is configured on a virtual server.
What components of F5 BIG-IP are impacted by CVE-2022-23025?
CVE-2022-23025 impacts various components of F5 BIG-IP, including Access Policy Manager, Advanced Firewall Manager, Application Security Manager, and Local Traffic Manager.