F5-K34525368: High severity f5 big-ip and big-iq centralized management vulnerability
Published Feb 1, 2023
·Updated
When a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause TMM to terminate.
Affected Software
5 affected componentsFixes available
F5 BIG-IP
F5 BIG-IP>=16.1.0<=16.1.3
16.1.3.3
F5 BIG-IP>=15.1.0<=15.1.7
15.1.8
F5 BIG-IP>=14.1.0<=14.1.5
14.1.5.3
F5 BIG-IP>=13.1.0<=13.1.5
Event History
Feb 1, 2023
Advisory Published
via F5·01:20 PM
Frequently Asked Questions
1
What is the severity of F5-K34525368?
F5-K34525368 is considered a high severity vulnerability due to the potential for TMM termination.
2
How do I fix F5-K34525368?
To fix F5-K34525368, upgrade to the recommended versions of F5 BIG-IP as specified in the advisory.
3
What causes the issue in F5-K34525368?
The issue in F5-K34525368 is caused by undisclosed traffic affecting the TMM when a SIP profile is configured on a Message Routing type virtual server.
4
Is my version of F5 BIG-IP affected by F5-K34525368?
If your version of F5 BIG-IP falls within the specified vulnerable ranges, it is affected by F5-K34525368.
5
What are the recommended versions to mitigate F5-K34525368?
The recommended versions to mitigate F5-K34525368 are 16.1.3.3, 15.1.8, and 14.1.5.3 for the respective affected ranges.