CVE-2023-22302: BIG-IP HTTP profile vulnerability
In BIG-IP versions 17.0.x before 17.0.0.2, and 16.1.x beginning in 16.1.2.2 to before 16.1.3.3, when an HTTP profile is configured on a virtual server and conditions beyond the attacker’s control exist on the target pool member, undisclosed requests sent to the BIG-IP system can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-22302.
What is the severity of CVE-2023-22302?
The severity of CVE-2023-22302 is medium with a CVSS score of 5.9.
Which software versions are affected by CVE-2023-22302?
The affected software versions are F5 Big-ip Access Policy Manager, F5 Big-ip Advanced Firewall Manager, F5 BIG-IP Analytics, F5 Big-ip Application Acceleration Manager, F5 BIG-IP Application Security Manager, F5 Big-ip Ddos Hybrid Defender, F5 Big-ip Domain Name System, F5 Big-ip Fraud Protection Service, F5 Big-ip Link Controller, F5 Big-ip Local Traffic Manager, F5 Big-ip Policy Enforcement Manager, and F5 Big-ip Ssl Orchestrator.
How can an attacker exploit CVE-2023-22302?
An attacker can exploit CVE-2023-22302 by sending undisclosed requests to the BIG-IP system when an HTTP profile is configured on a virtual server and conditions beyond the attacker's control exist on the target pool member.
Where can I find more information about CVE-2023-22302?
You can find more information about CVE-2023-22302 at the following link: [https://my.f5.com/manage/s/article/K58550078](https://my.f5.com/manage/s/article/K58550078)