CVE-2024-23314: BIG-IP HTTP/2 vulnerability
When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
F5 BIG-IP Nextto a version that resolves this vulnerability.Fixed in 1.8.1 - Upgrade
Upgrade
F5 BIG-IP and BIG-IQ Centralized Managementto a version that resolves this vulnerability.Fixed in 17.1.1 - Upgrade
Upgrade
F5 BIG-IP and BIG-IQ Centralized Managementto a version that resolves this vulnerability.Fixed in 16.1.4 - Upgrade
Upgrade
F5 BIG-IP and BIG-IQ Centralized Managementto a version that resolves this vulnerability.Fixed in 15.1.9
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23314?
CVE-2024-23314 has not been assigned a specific severity rating, but it can cause the Traffic Management Microkernel to terminate.
How do I fix CVE-2024-23314?
To resolve CVE-2024-23314, you should upgrade your F5 BIG-IP or BIG-IP Next Service Proxy for Kubernetes to the appropriate remedied version.
What versions are affected by CVE-2024-23314?
F5 BIG-IP versions 15.1.0 to 15.1.8, 16.1.0 to 16.1.3, 17.1.0, and BIG-IP Next Service Proxy for Kubernetes versions 1.5.0 to 1.8.0 are affected.
What components of F5 systems are impacted by CVE-2024-23314?
CVE-2024-23314 affects the Traffic Management Microkernel (TMM) within F5 BIG-IP and BIG-IP Next Service Proxy for Kubernetes.
Can CVE-2024-23314 lead to a denial of service?
Yes, CVE-2024-23314 can potentially lead to a denial of service by terminating the Traffic Management Microkernel.