BIG-IP and BIG-IQ AWS vulnerability CVE-2022-34844
Published Aug 4, 2022
7.5
HIGHCVSS 3.1
EPSS 0.72%
Description
In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP or BIG-IQ on Amazon Web Services (AWS) systems, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Successful exploitation relies on conditions outside of the attacker's control. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected products
-
- Version 15.1.xStatusaffectedConstraints<15.1.6.1
- Version 16.1.xStatusaffectedConstraints<16.1.3.1
- Version 13.1.0StatusunaffectedConstraints<13.1.x*
- Version 14.1.0StatusunaffectedConstraints<14.1.x*
- Version 17.0.0StatusunaffectedConstraints<17.0.x*
- Version
-
- Version 8.0.0StatusaffectedConstraints<8.x*
- Version 7.0.0StatusunaffectedConstraints<7.x*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| F5 | Big-IP | n/a |
| ||||||||||||||||||
| F5 | BIG-IQ Centralized Management | n/a |
|
- ≥ 15.1.0 · < 15.1.6.1
- ≥ 16.1.0 · < 16.1.3.1
- ≥ 15.1.0 · < 15.1.6.1
- ≥ 16.1.0 · < 16.1.3.1
- ≥ 15.1.0 · < 15.1.6.1
- ≥ 16.1.0 · < 16.1.3.1
- ≥ 15.1.0 · < 15.1.6.1
- ≥ 16.1.0 · < 16.1.3.1
- ≥ 15.1.0 · < 15.1.6.1
- ≥ 16.1.0 · < 16.1.3.1
- ≥ 15.1.0 · < 15.1.6.1
- ≥ 16.1.0 · < 16.1.3.1
- ≥ 15.1.0 · < 15.1.6.1
- ≥ 16.1.0 · < 16.1.3.1
- ≥ 15.1.0 · < 15.1.6.1
- ≥ 16.1.0 · < 16.1.3.1
- ≥ 15.1.0 · < 15.1.6.1
- ≥ 16.1.0 · < 16.1.3.1
- ≥ 15.1.0 · < 15.1.6.1
- ≥ 16.1.0 · < 16.1.3.1
- ≥ 15.1.0 · < 15.1.6.1
- ≥ 16.1.0 · < 16.1.3.1
- 7.0.0
- 7.1.0
- 8.0.0
- 8.1.0
- 8.2.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (1)
- https://support.f5.com/csp/article/K34511555 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://support.f5.com/csp/article/K34511555 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.