CVE-2023-23555: BIG-IP Virtual Edition vulnerability
On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 and 14.1.x beginning in 14.1.5 to before 14.1.5.3, and BIG-IP SPK beginning in 1.5.0 to before 1.6.0, when FastL4 profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Other sources
When FastL4 profile is configured on a virtual server in BIG-IP Virtual Edition, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
— F5
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23555?
The severity of CVE-2023-23555 is high with a severity value of 7.5.
How does CVE-2023-23555 affect F5 Big-ip Access Policy Manager?
CVE-2023-23555 affects F5 Big-ip Access Policy Manager versions 14.1.5 to before 14.1.5.3.
What is the impact of CVE-2023-23555?
CVE-2023-23555 allows undisclosed traffic to cause the Traffic Management Microkernel to fail, causing a denial of service.
How do I fix CVE-2023-23555?
To fix CVE-2023-23555, users should upgrade their affected software to version 14.1.5.3 or later.
Where can I find more information about CVE-2023-23555?
More information about CVE-2023-23555 can be found at the F5 support website: https://my.f5.com/manage/s/article/K24572686