CVE-2023-24594: BIG-IP TMM SSL vulnerability
When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-24594?
CVE-2023-24594 is a vulnerability where undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization on a Virtual Server with an SSL profile configured.
Which software versions are affected by CVE-2023-24594?
CVE-2023-24594 affects F5 BIG-IP Access Policy Manager versions 14.1.5, 15.1.4.1, and 16.1.2, F5 BIG-IP Advanced Firewall Manager versions 14.1.5, 15.1.4.1, and 16.1.2, F5 BIG-IP Advanced Web Application Firewall versions 14.1.5, 15.1.4.1, and 16.1.2, and many other F5 products.
What is the severity of CVE-2023-24594?
CVE-2023-24594 has a severity value of 5.3, which is considered medium.
How can I fix CVE-2023-24594?
To fix CVE-2023-24594, it is recommended to upgrade to a non-vulnerable version of the affected F5 product or apply the necessary patches provided by F5 Networks.
Where can I find more information about CVE-2023-24594?
More information about CVE-2023-24594 can be found at the following reference: [link](https://my.f5.com/manage/s/article/K000133132)