CVE-2022-34655: TMM vulnerability CVE-2022-34655
In BIG-IP Versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an iRule containing the HTTP::payload command is configured on a virtual server, undisclosed traffic can cause Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this F5 BIG-IP vulnerability?
The vulnerability ID for this F5 BIG-IP vulnerability is CVE-2022-34655.
What is the severity level of CVE-2022-34655?
CVE-2022-34655 has a severity level of 7.5 (high).
Which versions of F5 BIG-IP are affected by CVE-2022-34655?
The affected versions are 16.0.x before 16.0.1.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5.
How does the vulnerability in CVE-2022-34655 manifest?
The vulnerability in CVE-2022-34655 manifests when an iRule containing the HTTP::payload command is configured on a virtual server, allowing undisclosed traffic to cause Traffic Management Microkernel (TMM) to terminate.
Is there a fix for CVE-2022-34655?
Yes, updating to BIG-IP versions 16.0.1.1, 15.1.6.1, or 14.1.5 will resolve the vulnerability.