First published: Mon Jan 09 2023(Updated: )
When an HTTP profile is configured on a virtual server and conditions beyond the attacker’s control exist on the target pool member, undisclosed requests sent to the BIG-IP system can cause the Traffic Management Microkernel (TMM) to terminate.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP and BIG-IQ Centralized Management | =17.0.0 | 17.1.0 |
F5 BIG-IP and BIG-IQ Centralized Management | >=16.1.2.2<=16.1.3 | 16.1.3.3 |
F5 BIG-IP and BIG-IQ Centralized Management |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of F5-K58550078 is considered critical due to the potential for denial of service attacks causing Traffic Management Microkernel termination.
To fix F5-K58550078, upgrade to the recommended versions of BIG-IP: 17.1.0 or 16.1.3.3, based on your current version.
Affected versions for F5-K58550078 include BIG-IP versions 17.0.0 and between 16.1.2.2 and 16.1.3.
The impact of F5-K58550078 includes potential interruption of services due to Traffic Management Microkernel termination.
There are no official workarounds for F5-K58550078, making an upgrade the best option to mitigate the risk.