F5-K24572686: High severity f5 big-ip and big-iq centralized management vulnerability
Published Feb 1, 2023
·Updated
When FastL4 profile is configured on a virtual server in BIG-IP Virtual Edition, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Affected Software
4 affected componentsFixes available
F5 BIG-IP
F5 BIG-IP>=15.1.4<=15.1.7
15.1.8
F5 BIG-IP=14.1.5
14.1.5.3
F5 BIG-IP SPK=1.5
1.6
Event History
Feb 1, 2023
Advisory Published
via F5·01:20 PM
Frequently Asked Questions
1
What is the severity of F5-K24572686?
The severity of F5-K24572686 is currently classified as critical.
2
How do I fix F5-K24572686?
To fix F5-K24572686, upgrade your BIG-IP version to 15.1.8, 14.1.5.3, or 1.6 based on your current version.
3
What causes F5-K24572686?
F5-K24572686 is caused by undisclosed traffic impacting the Traffic Management Microkernel (TMM) when a FastL4 profile is used.
4
Which versions of F5 BIG-IP are affected by F5-K24572686?
Versions F5 BIG-IP 15.1.4 to 15.1.7 and F5 BIG-IP 14.1.5 are affected by F5-K24572686.
5
Is F5-K24572686 associated with any specific product?
Yes, F5-K24572686 specifically impacts the F5 BIG-IP and F5 BIG-IP Service Proxy for Kubernetes products.