CVE-2022-23028

On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when global AFM SYN cookie protection (TCP Half Open flood vector) is activated in the AFM Device Dos or DOS profile, certain types of TCP connections will fail. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
Link Resource
https://support.f5.com/csp/article/K16101409 Mitigation Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*

History

01 Feb 2022, 18:34

Type Values Removed Values Added
CWE CWE-682
CPE cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
First Time F5
F5 big-ip Advanced Firewall Manager
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 5.3
References (MISC) https://support.f5.com/csp/article/K16101409 - (MISC) https://support.f5.com/csp/article/K16101409 - Mitigation, Vendor Advisory

25 Jan 2022, 20:19

Type Values Removed Values Added
New CVE

Information

Published : 2022-01-25 20:15

Updated : 2023-12-10 14:09


NVD link : CVE-2022-23028

Mitre link : CVE-2022-23028

CVE.ORG link : CVE-2022-23028


JSON object : View

Products Affected

f5

  • big-ip_advanced_firewall_manager
CWE
CWE-682

Incorrect Calculation