CVE-2022-23027: Medium severity f5 access policy manager vulnerability
On BIG-IP versions 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, 13.1.x beginning in 13.1.3.6, 12.1.5.3-12.1.6, and 11.6.5.2, when a FastL4 profile and an HTTP, FIX, and/or hash persistence profile are configured on the same virtual server, undisclosed requests can cause the virtual server to stop processing new client connections. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23027?
CVE-2022-23027 has a severity rating of medium as it can cause a denial of service condition on the affected BIG-IP versions.
How do I fix CVE-2022-23027?
To fix CVE-2022-23027, you should upgrade to the patched versions of BIG-IP, specifically versions 15.1.4, 14.1.4.4, 13.1.4, or later.
Which versions are affected by CVE-2022-23027?
Affected versions include BIG-IP versions 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, 13.1.x beginning in 13.1.3.6, 12.1.5.3-12.1.6, and 11.6.5.2.
What components are impacted by CVE-2022-23027?
CVE-2022-23027 impacts virtual servers configured with both FastL4 profiles and persistence profiles like HTTP, FIX, and hash.
Can CVE-2022-23027 be exploited remotely?
Yes, CVE-2022-23027 can be exploited remotely, potentially allowing attackers to send undisclosed requests that could cause a virtual server to stop processing.