CVE-2023-22839: BIG-IP DNS profile vulnerability
On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled, undisclosed requests cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What versions of F5 BIG-IP are affected by CVE-2023-22839?
F5 BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x are affected.
What is the severity of CVE-2023-22839?
The severity of CVE-2023-22839 has not been disclosed, but it potentially affects core functionalities of the affected systems.
How do I fix CVE-2023-22839?
To fix CVE-2023-22839, upgrade to the recommended patched versions: 17.0.0.2, 16.1.3.3, 15.1.8.1, or 14.1.5.3.
What is the impact of CVE-2023-22839?
The impact of CVE-2023-22839 involves potential disruption to DNS services when the Rapid Response Mode setting is enabled.
Is there a workaround for CVE-2023-22839?
Disabling the Rapid Response Mode setting on affected DNS profiles may serve as a temporary workaround for CVE-2023-22839.