CVE-2022-23024
HIGHBIG-IP AFM DoS via IPsec ALG Logging Profile (13.1.x < 13.1.4, 14.1.x < 14.1.4.2, 15.1.x < 15.1.4.1, 16.x < 16.1.0)
Title source: llmDescription
On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.2, and all versions of 13.1.x, when the IPsec application layer gateway (ALG) logging profile is configured on an IPsec ALG virtual server, undisclosed IPsec traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://support.f5.com/csp/article/K54892865
Scores
CVSS v3
7.5
EPSS
0.0065
EPSS Percentile
71.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-400
Status
published
Products (1)
f5/big-ip_advanced_firewall_manager
13.1.0 - 13.1.4
Published
Jan 25, 2022
Tracked Since
Feb 18, 2026