CVE-2022-28705
HIGHF5 BIG-IP <16.1.2.2, 15.1.5.1, 14.1.4.6, 13.1.5 - DoS
Title source: llmDescription
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, on platforms with an ePVA and the pva.fwdaccel BigDB variable enabled, undisclosed requests to a virtual server with a FastL4 profile that has ePVA acceleration enabled can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://support.f5.com/csp/article/K52340447
Scores
CVSS v3
7.5
EPSS
0.0065
EPSS Percentile
71.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-190
Status
published
Products (50)
f5/big-ip_access_policy_manager
13.1.0
f5/big-ip_access_policy_manager
13.1.1
f5/big-ip_access_policy_manager
13.1.3
f5/big-ip_access_policy_manager
13.1.4
f5/big-ip_access_policy_manager
13.1.5
f5/big-ip_access_policy_manager
14.1.0
f5/big-ip_access_policy_manager
14.1.2
f5/big-ip_access_policy_manager
14.1.3
f5/big-ip_access_policy_manager
14.1.4
f5/big-ip_access_policy_manager
15.1.0
... and 40 more
Published
May 05, 2022
Tracked Since
Feb 18, 2026