CVE-2022-41694: BIG-IP and BIG-IQ mcpd vulnerability CVE-2022-41694
In BIG-IP versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, and BIG-IQ versions 8.x before 8.2.0.1 and all versions of 7.x, when an SSL key is imported on a BIG-IP or BIG-IQ system, undisclosed input can cause MCPD to terminate.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
F5 BIG-IP (mcpd)to a version that resolves this vulnerability.Fixed in 16.1.3 - Upgrade
Upgrade
F5 BIG-IP (mcpd)to a version that resolves this vulnerability.Fixed in 15.1.6.1 - Upgrade
Upgrade
F5 BIG-IP (mcpd)to a version that resolves this vulnerability.Fixed in 14.1.5 - Upgrade
Upgrade
F5 BIG-IQ (mcpd)to a version that resolves this vulnerability.Fixed in 8.2.0.1 - Compensating control
Avoid importing SSL keys into the affected BIG-IP/BIG-IQ versions until you upgrade to the fixed releases (16.1.3, 15.1.6.1, 14.1.5, 8.2.0.1).
Event History
Frequently Asked Questions
What is the severity of CVE-2022-41694?
The severity of CVE-2022-41694 is medium with a severity value of 4.9.
Which versions of BIG-IP are affected by CVE-2022-41694?
BIG-IP versions 13.1.x, 14.1.x, 15.1.x, and 16.1.x are affected by CVE-2022-41694.
Which versions of BIG-IQ are affected by CVE-2022-41694?
BIG-IQ versions 7.x and 8.x are affected by CVE-2022-41694.
How can I fix CVE-2022-41694?
To fix CVE-2022-41694, update to BIG-IP versions 16.1.3, 15.1.6.1, 14.1.5, or later, and update to BIG-IQ versions 8.2.0.1 or later.
Where can I find more information about CVE-2022-41694?
More information about CVE-2022-41694 can be found at the following link: [support.f5.com/csp/article/K64829234](https://support.f5.com/csp/article/K64829234)