7.5

CVE-2022-32455

In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when a BIG-IP LTM Client SSL profile is configured on a virtual server to perform client certificate authentication with session tickets enabled, undisclosed requests cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Data is provided by the National Vulnerability Database (NVD)
F5Big-ip Access Policy Manager Version >= 13.1.0 <= 13.1.5
F5Big-ip Access Policy Manager Version >= 14.1.0 < 14.1.5
F5Big-ip Access Policy Manager Version >= 15.1.0 < 15.1.6.1
F5Big-ip Access Policy Manager Version >= 16.1.0 < 16.1.2.2
F5Big-ip Advanced Firewall Manager Version >= 13.1.0 <= 13.1.5
F5Big-ip Advanced Firewall Manager Version >= 14.1.0 < 14.1.5
F5Big-ip Advanced Firewall Manager Version >= 15.1.0 < 15.1.6.1
F5Big-ip Advanced Firewall Manager Version >= 16.1.0 < 16.1.2.2
F5Big-ip Analytics Version >= 13.1.0 <= 13.1.5
F5Big-ip Analytics Version >= 14.1.0 < 14.1.5
F5Big-ip Analytics Version >= 15.1.0 < 15.1.6.1
F5Big-ip Analytics Version >= 16.1.0 < 16.1.2.2
F5Big-ip Application Acceleration Manager Version >= 13.1.0 <= 13.1.5
F5Big-ip Application Acceleration Manager Version >= 14.1.0 < 14.1.5
F5Big-ip Application Acceleration Manager Version >= 15.1.0 < 15.1.6.1
F5Big-ip Application Acceleration Manager Version >= 16.1.0 < 16.1.2.2
F5Big-ip Application Security Manager Version >= 13.1.0 <= 13.1.5
F5Big-ip Application Security Manager Version >= 14.1.0 < 14.1.5
F5Big-ip Application Security Manager Version >= 15.1.0 < 15.1.6.1
F5Big-ip Application Security Manager Version >= 16.1.0 < 16.1.2.2
F5Big-ip Domain Name System Version >= 13.1.0 <= 13.1.5
F5Big-ip Domain Name System Version >= 14.1.0 < 14.1.5
F5Big-ip Domain Name System Version >= 15.1.0 < 15.1.6.1
F5Big-ip Domain Name System Version >= 16.1.0 < 16.1.2.2
F5Big-ip Fraud Protection Service Version >= 13.1.0 <= 13.1.5
F5Big-ip Fraud Protection Service Version >= 14.1.0 < 14.1.5
F5Big-ip Fraud Protection Service Version >= 15.1.0 < 15.1.6.1
F5Big-ip Fraud Protection Service Version >= 16.1.0 < 16.1.2.2
F5Big-ip Global Traffic Manager Version >= 13.1.0 <= 13.1.5
F5Big-ip Global Traffic Manager Version >= 14.1.0 < 14.1.5
F5Big-ip Global Traffic Manager Version >= 15.1.0 < 15.1.6.1
F5Big-ip Global Traffic Manager Version >= 16.1.0 < 16.1.2.2
F5Big-ip Link Controller Version >= 13.1.0 <= 13.1.5
F5Big-ip Link Controller Version >= 14.1.0 < 14.1.5
F5Big-ip Link Controller Version >= 15.1.0 < 15.1.6.1
F5Big-ip Link Controller Version >= 16.1.0 < 16.1.2.2
F5Big-ip Local Traffic Manager Version >= 13.1.0 <= 13.1.5
F5Big-ip Local Traffic Manager Version >= 14.1.0 < 14.1.5
F5Big-ip Local Traffic Manager Version >= 15.1.0 < 15.1.6.1
F5Big-ip Local Traffic Manager Version >= 16.1.0 < 16.1.2.2
F5Big-ip Policy Enforcement Manager Version >= 13.1.0 <= 13.1.5
F5Big-ip Policy Enforcement Manager Version >= 14.1.0 < 14.1.5
F5Big-ip Policy Enforcement Manager Version >= 15.1.0 < 15.1.6.1
F5Big-ip Policy Enforcement Manager Version >= 16.1.0 < 16.1.2.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.36% 0.575
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
f5sirt@f5.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.