CVE-2022-41833: BIG-IP iRule vulnerability CVE-2022-41833
In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect command is configured on a virtual server, undisclosed requests can cause Traffic Management Microkernel (TMM) to terminate.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
For BIG-IP 13.1.x, avoid configuring iRules that contain the HTTP::collect command on virtual servers to prevent undisclosed requests from causing TMM termination.
Event History
Frequently Asked Questions
What is CVE-2022-41833?
CVE-2022-41833 is a vulnerability found in all BIG-IP 13.1.x versions that can cause Traffic Management Microkernel (TMM) to terminate when an iRule containing the HTTP::collect command is configured on a virtual server.
Which software versions are affected by CVE-2022-41833?
CVE-2022-41833 affects all BIG-IP 13.1.x versions between 13.1.0 and 13.1.5, including F5 BIG-IP Access Policy Manager, Advanced Firewall Manager, Analytics, Application Acceleration Manager, Application Security Manager, Domain Name System, Fraud Protection Service, Global Traffic Manager, Link Controller, Local Traffic Manager, and Policy Enforcement Manager.
How severe is CVE-2022-41833?
CVE-2022-41833 has a severity rating of 7.5 (High).
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-41833?
The Common Weakness Enumeration (CWE) ID for CVE-2022-41833 is 400.
How can I fix CVE-2022-41833?
To fix CVE-2022-41833, upgrade to a version of BIG-IP that is not affected by this vulnerability or apply the necessary patches provided by F5 Networks.