CVE-2022-41691: BIG-IP Advanced WAF/ASM bd vulnerability CVE-2022-41691
Published Oct 19, 2022
·Updated
When a BIG-IP Advanced WAF/ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.
Affected Software
2 affected components
F5 Big-ip Advanced Web Application Firewall>=14.1.0<14.1.5.2
F5 BIG-IP Application Security Manager>=14.1.0<14.1.5.2
Event History
Oct 19, 2022
CVE Published
via MITRE·09:19 PM
Data Sourced
via MITRE·09:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-41691?
CVE-2022-41691 is a vulnerability in BIG-IP Advanced WAF/ASM security policy configuration that can cause the bd process to terminate when undisclosed requests are made.
2
How does CVE-2022-41691 affect F5 Big-IP Advanced Web Application Firewall?
CVE-2022-41691 affects F5 Big-IP Advanced Web Application Firewall versions between 14.1.0 and 14.1.5.2.
3
How does CVE-2022-41691 affect F5 BIG-IP Application Security Manager?
CVE-2022-41691 affects F5 BIG-IP Application Security Manager versions between 14.1.0 and 14.1.5.2.
4
What is the severity of CVE-2022-41691?
CVE-2022-41691 has a severity rating of 7.5 (High).
5
How can I fix CVE-2022-41691?
To fix CVE-2022-41691, upgrade F5 Big-IP Advanced Web Application Firewall or F5 BIG-IP Application Security Manager to a version beyond 14.1.5.2 as recommended by F5 Networks.