CVE-2022-34651: BIG-IP TLS 1.3 iRule vulnerability CVE-2022-34651
In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, when an LTM Client or Server SSL profile with TLS 1.3 enabled is configured on a virtual server, along with an iRule that calls HTTP::respond, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-34651?
CVE-2022-34651 refers to a vulnerability in BIG-IP versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1 that can cause the Traffic Management Microkernel (TMM) to terminate when certain requests are made.
How does CVE-2022-34651 impact F5 BIG-IP products?
CVE-2022-34651 can affect the following F5 BIG-IP products: Access Policy Manager, Advanced Firewall Manager, Analytics, Application Acceleration Manager, Application Security Manager, Domain Name System, Fraud Protection Service, Global Traffic Manager, Link Controller, Local Traffic Manager, and Policy Enforcement Manager.
What is the severity of CVE-2022-34651?
CVE-2022-34651 has a severity level of high with a CVSS score of 7.5.
How can I fix CVE-2022-34651?
To fix CVE-2022-34651, you should upgrade your BIG-IP software to versions 15.1.6.1 or 16.1.3.1 or later.
Where can I find more information about CVE-2022-34651?
You can find more information about CVE-2022-34651 on the F5 support website at the following link: https://support.f5.com/csp/article/K59197053