CVE-2022-28705

HIGH

F5 BIG-IP <16.1.2.2, 15.1.5.1, 14.1.4.6, 13.1.5 - DoS

Title source: llm
STIX 2.1

Description

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, on platforms with an ePVA and the pva.fwdaccel BigDB variable enabled, undisclosed requests to a virtual server with a FastL4 profile that has ePVA acceleration enabled can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://support.f5.com/csp/article/K52340447

Scores

CVSS v3 7.5
EPSS 0.0065
EPSS Percentile 71.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-190
Status published
Products (50)
f5/big-ip_access_policy_manager 13.1.0
f5/big-ip_access_policy_manager 13.1.1
f5/big-ip_access_policy_manager 13.1.3
f5/big-ip_access_policy_manager 13.1.4
f5/big-ip_access_policy_manager 13.1.5
f5/big-ip_access_policy_manager 14.1.0
f5/big-ip_access_policy_manager 14.1.2
f5/big-ip_access_policy_manager 14.1.3
f5/big-ip_access_policy_manager 14.1.4
f5/big-ip_access_policy_manager 15.1.0
... and 40 more
Published May 05, 2022
Tracked Since Feb 18, 2026