F5 Products Multiple Vulnerabilities
RISK: Medium Risk
TYPE: Operating Systems - Networks OS
Multiple vulnerabilities were identified in F5 Products . A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and remote code execution on the targeted system.
[Updated on 2022-05-06]
Updated Vulnerability Identifier, Source and Related Links.
Impact
- Denial of Service
- Remote Code Execution
System / Technologies affected
F5OS-A
- version 1.0.0 - 1.0.1
F5OS-C
- version 1.1.0 - 1.4.0
BIG-IP ASM
- version 17.0.0
- version 16.1.0 - 16.1.2
- version 15.1.0 - 15.1.5
- version 14.1.0 - 14.1.4
- version 13.1.0 - 13.1.5
- version 12.1.0 - 12.1.6
- version 11.6.1 - 11.6.5
BIG-IP DNS
- version 17.0.0
- version 16.1.0 - 16.1.2
- version 15.1.0 - 15.1.5
- version 14.1.0 - 14.1.4
- version 13.1.0 - 13.1.5
- version 12.1.0 - 12.1.6
- version 11.6.1 - 11.6.5
BIG-IP (all other modules)
- version 17.0.0
- version 16.1.0 - 16.1.2
- version 15.1.0 - 15.1.5
- version 14.1.0 - 14.1.4
- version 13.1.0 - 13.1.5
- version 12.1.0 - 12.1.6
- version 11.6.1 - 11.6.5
BIG-IQ Centralized Management
- version 8.0.0 - 8.2.0
- version 7.0.0 - 7.1.0
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
- https://support.f5.com/csp/article/K52308021
- https://support.f5.com/csp/article/K23231802
- https://support.f5.com/csp/article/K19473898
Vulnerability Identifier
- CVE-2021-46143
- CVE-2022-23218
- CVE-2022-23219
- CVE-2022-23515
- CVE-2022-23852
- CVE-2022-25235
- CVE-2022-25236
- CVE-2022-25315
Source
Related Link
Related Tags
Share with