CVE-2023-22839

On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled, undisclosed requests cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
Link Resource
https://my.f5.com/manage/s/article/K37708118 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:f5:big-ip_10000s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_10000s:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:f5:big-ip_10200v_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_10200v:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:f5:big-ip_10200v-ssl_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_10200v-ssl:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:f5:big-ip_12000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_12000:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:f5:big-ip_5000s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_5000s:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:f5:big-ip_5200v_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_5200v:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:f5:big-ip_5200v-ssl_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_5200v-ssl:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:f5:big-ip_7000s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_7000s:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:f5:big-ip_7200v_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_7200v:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:f5:big-ip_7200v-ssl_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_7200v-ssl:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:f5:big-ip_i10600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i10600:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:f5:big-ip_i10800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i10800:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:f5:big-ip_i11600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i11600:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:f5:big-ip_i11800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i11800:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:f5:big-ip_i15600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i15600:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:f5:big-ip_i15800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i15800:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:f5:big-ip_i5600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i5600:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:f5:big-ip_i5800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i5800:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:f5:big-ip_i7600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i7600:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:f5:big-ip_i7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i7800:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:f5:r10600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:r10600:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:f5:r10800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:r10800:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:f5:r10900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:r10900:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:f5:r5600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:r5600:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:f5:r5800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:r5800:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:f5:r5900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:r5900:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:f5:velos_bx110_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:velos_bx110:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:f5:viprion_b2100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:viprion_b2100:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:f5:viprion_b2150_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:viprion_b2150:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:f5:viprion_b2250_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:viprion_b2250:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:f5:viprion_b4300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:viprion_b4300:-:*:*:*:*:*:*:*

Configuration 33 (hide)

AND
cpe:2.3:o:f5:viprion_b4450_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:viprion_b4450:-:*:*:*:*:*:*:*

History

07 Nov 2023, 04:07

Type Values Removed Values Added
Summary On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled, undisclosed requests cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled, undisclosed requests cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

10 Feb 2023, 00:31

Type Values Removed Values Added
CWE CWE-476
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:h:f5:big-ip_7200v:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_i10800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_i15600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:r10900:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_10000s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:viprion_b4300:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:viprion_b2150:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_10200v-ssl:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_7200v-ssl_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_10200v-ssl_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_i7600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:r5800:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:velos_bx110_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_7200v_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:viprion_b2100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i10600:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:viprion_b2250:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_i5600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_10200v_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_i10600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_i7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i15800:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_5200v_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i5800:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:velos_bx110:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:r5900:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_10000s:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:viprion_b2250_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_12000:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_5000s:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i11600:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_7200v-ssl:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:r10600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i5600:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_7000s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_i5800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_10200v:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:r10800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:viprion_b4300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:viprion_b4450_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_i11600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i7800:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_5200v-ssl:-:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_i15800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:r10800:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:viprion_b4450:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i10800:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:viprion_b2150_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_i11800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:r5800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i7600:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:r5900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_12000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:r5600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_5000s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_7000s:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:r10600:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:viprion_b2100:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_5200v:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i15600:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:r5600:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:big-ip_5200v-ssl_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:f5:r10900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:f5:big-ip_i11800:-:*:*:*:*:*:*:*
First Time F5 big-ip 5000s
F5 r10900
F5 r5800 Firmware
F5 big-ip 10200v-ssl
F5 big-ip I11600 Firmware
F5 big-ip 5000s Firmware
F5 viprion B2150 Firmware
F5 big-ip 12000
F5 big-ip I15600
F5 r10600
F5 big-ip I7800
F5 viprion B2250 Firmware
F5 big-ip 5200v
F5 r5900
F5 viprion B2100 Firmware
F5 big-ip 10200v Firmware
F5 big-ip 7200v
F5 velos Bx110
F5 r5800
F5 big-ip 10200v-ssl Firmware
F5 big-ip I7600
F5 viprion B4450
F5 big-ip I5800 Firmware
F5 big-ip 5200v Firmware
F5 big-ip 10000s Firmware
F5 big-ip I5800
F5 viprion B2250
F5 big-ip 5200v-ssl
F5 big-ip Local Traffic Manager
F5 r10800
F5 big-ip I11800 Firmware
F5 big-ip Domain Name System
F5 big-ip I5600
F5 big-ip I15600 Firmware
F5 big-ip 12000 Firmware
F5 r10600 Firmware
F5 big-ip 7000s Firmware
F5 viprion B2150
F5 big-ip 7200v Firmware
F5 big-ip I15800 Firmware
F5 velos Bx110 Firmware
F5 big-ip I7600 Firmware
F5 big-ip I10600 Firmware
F5 big-ip 7000s
F5 big-ip 10000s
F5 r5600 Firmware
F5 big-ip I10800 Firmware
F5 viprion B4300 Firmware
F5 r10800 Firmware
F5 r10900 Firmware
F5 r5900 Firmware
F5 big-ip I7800 Firmware
F5 big-ip I10800
F5 big-ip 7200v-ssl Firmware
F5 viprion B4300
F5 big-ip I15800
F5 big-ip 10200v
F5 big-ip I10600
F5 big-ip 5200v-ssl Firmware
F5 big-ip I11800
F5 big-ip 7200v-ssl
F5
F5 r5600
F5 viprion B4450 Firmware
F5 big-ip I5600 Firmware
F5 viprion B2100
F5 big-ip I11600
References (MISC) https://my.f5.com/manage/s/article/K37708118 - (MISC) https://my.f5.com/manage/s/article/K37708118 - Vendor Advisory

01 Feb 2023, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-01 18:15

Updated : 2023-12-10 14:48


NVD link : CVE-2023-22839

Mitre link : CVE-2023-22839

CVE.ORG link : CVE-2023-22839


JSON object : View

Products Affected

f5

  • big-ip_12000
  • big-ip_i15800
  • big-ip_12000_firmware
  • big-ip_i10600
  • viprion_b2100
  • big-ip_i7600_firmware
  • big-ip_i7800_firmware
  • big-ip_i10600_firmware
  • big-ip_i5800
  • big-ip_local_traffic_manager
  • big-ip_i10800_firmware
  • big-ip_7200v_firmware
  • r5600
  • big-ip_7200v-ssl_firmware
  • viprion_b4450
  • big-ip_i15600
  • big-ip_5200v
  • big-ip_10200v-ssl
  • big-ip_7200v-ssl
  • viprion_b4300_firmware
  • viprion_b4450_firmware
  • velos_bx110
  • big-ip_i15800_firmware
  • viprion_b2250
  • big-ip_domain_name_system
  • viprion_b2150
  • big-ip_i15600_firmware
  • big-ip_i10800
  • big-ip_10200v_firmware
  • big-ip_i11800_firmware
  • viprion_b2150_firmware
  • r5800_firmware
  • big-ip_i5600_firmware
  • big-ip_i7800
  • r5800
  • r10800
  • big-ip_10200v
  • big-ip_i5600
  • big-ip_i11600_firmware
  • r10900
  • big-ip_i5800_firmware
  • big-ip_7200v
  • r10900_firmware
  • viprion_b2250_firmware
  • big-ip_5200v_firmware
  • big-ip_5200v-ssl
  • big-ip_7000s
  • velos_bx110_firmware
  • r5900
  • r10600
  • big-ip_10200v-ssl_firmware
  • big-ip_7000s_firmware
  • big-ip_i7600
  • r10600_firmware
  • r10800_firmware
  • r5600_firmware
  • big-ip_10000s_firmware
  • big-ip_5000s
  • big-ip_i11800
  • r5900_firmware
  • big-ip_5200v-ssl_firmware
  • viprion_b2100_firmware
  • big-ip_10000s
  • big-ip_5000s_firmware
  • big-ip_i11600
  • viprion_b4300
CWE
CWE-476

NULL Pointer Dereference