CVE-2022-41813: BIG-IP PEM and AFM TMUI, TMSH and iControl vulnerability CVE-2022-41813
In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when BIG-IP is provisioned with PEM or AFM module, an undisclosed input can cause Traffic Management Microkernel (TMM) to terminate.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
F5 BIG-IPto a version that resolves this vulnerability.Fixed in 17.0.0 - Upgrade
Upgrade
F5 BIG-IPto a version that resolves this vulnerability.Fixed in 16.1.3.1 - Upgrade
Upgrade
F5 BIG-IPto a version that resolves this vulnerability.Fixed in 15.1.6.1 - Upgrade
Upgrade
F5 BIG-IPto a version that resolves this vulnerability.Fixed in 14.1.5 - Upgrade
Upgrade
BIG-IP (PEM/AFM)to a version that resolves this vulnerability.Fixed in 16.1.3.1 - Upgrade
Upgrade
BIG-IP (PEM/AFM)to a version that resolves this vulnerability.Fixed in 15.1.6.1 - Upgrade
Upgrade
BIG-IP (PEM/AFM)to a version that resolves this vulnerability.Fixed in 14.1.5 - Upgrade
Upgrade
BIG-IP (PEM/AFM)to a version that resolves this vulnerability.Fixed in 13.1.x
Event History
Frequently Asked Questions
What is CVE-2022-41813?
CVE-2022-41813 is a vulnerability found in F5 BIG-IP Advanced Firewall Manager and BIG-IP Policy Enforcement Manager versions 13.1.x, 14.1.x, 15.1.x, and 16.1.x.
How does CVE-2022-41813 impact F5 BIG-IP?
CVE-2022-41813 can cause the Traffic Management Microkernel (TMM) to terminate on BIG-IP devices provisioned with the PEM or AFM module.
What is the severity of CVE-2022-41813?
The severity of CVE-2022-41813 is medium with a CVSS score of 6.5.
Which versions of F5 BIG-IP are affected by CVE-2022-41813?
CVE-2022-41813 affects F5 BIG-IP Advanced Firewall Manager and BIG-IP Policy Enforcement Manager versions 13.1.x, 14.1.x, 15.1.x, and 16.1.x.
Is there a fix available for CVE-2022-41813?
Yes, F5 has released fixed versions to address the vulnerability.