CVE-2022-36795

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/10/2022
Last modified:
21/10/2022

Description

In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, and 14.1.x before 14.1.5.1, when an LTM TCP profile with Auto Receive Window Enabled is configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* 14.1.0 (including) 14.1.5.1 (excluding)
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* 15.1.0 (including) 15.1.7 (excluding)
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* 16.1.0 (including) 16.1.3.1 (excluding)
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* 17.0.0 (including) 17.0.0.1 (excluding)
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* 14.1.0 (including) 14.1.5.1 (excluding)
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* 15.1.0 (including) 15.1.7 (excluding)
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* 16.1.0 (including) 16.1.3.1 (excluding)
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* 17.0.0 (including) 17.0.0.1 (excluding)
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* 14.1.0 (including) 14.1.5.1 (excluding)
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* 15.1.0 (including) 15.1.7 (excluding)
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* 16.1.0 (including) 16.1.3.1 (excluding)
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* 17.0.0 (including) 17.0.0.1 (excluding)
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* 14.1.0 (including) 14.1.5.1 (excluding)
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* 15.1.0 (including) 15.1.7 (excluding)
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* 16.1.0 (including) 16.1.3.1 (excluding)


References to Advisories, Solutions, and Tools