CVE-2023-22842: BIG-IP SIP profile vulnerability
On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-22842?
CVE-2023-22842 is considered a medium severity vulnerability that can cause the Traffic Management Microkernel (TMM) to terminate.
How do I fix CVE-2023-22842?
To fix CVE-2023-22842, upgrade to F5 BIG-IP versions 16.1.3.3 or later, 15.1.8.1 or later, 14.1.5.3 or later, or ensure you are not using any versions of 13.1.x.
What systems are affected by CVE-2023-22842?
CVE-2023-22842 affects F5 BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x.
Is there a workaround for CVE-2023-22842?
There is no documented workaround for CVE-2023-22842 other than upgrading to a fixed version.
When was CVE-2023-22842 discovered?
CVE-2023-22842 was disclosed in 2023.