CVE-2023-22839

HIGHCVSS 7.5/10EPSS 0.63%

Last modified

CVE-2023-22839 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled, undisclosed requests cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. . EPSS estimates a 0.63% chance of exploitation in the next 30 days.

Description

On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled, undisclosed requests cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
0.63%

45.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
F5Big-Ip Domain Name System>= 13.1.0, <= 13.1.5
F5Big-Ip Domain Name System>= 14.1.0, < 14.1.5.3
F5Big-Ip Domain Name System>= 15.1.0, < 15.1.7
F5Big-Ip Domain Name System>= 16.1.0, < 16.1.3.3
F5Big-Ip Domain Name System>= 17.0.0, < 17.0.0.2
F5Big-Ip Local Traffic Manager>= 13.1.0, <= 13.1.5
F5Big-Ip Local Traffic Manager>= 14.1.0, < 14.1.5.3
F5Big-Ip Local Traffic Manager>= 15.1.0, < 15.1.7
F5Big-Ip Local Traffic Manager>= 16.1.0, < 16.1.3.3
F5Big-Ip Local Traffic Manager>= 17.0.0, < 17.0.0.2
F5Big-Ip 10000s FirmwareAll versions
F5Big-Ip 10200v FirmwareAll versions
F5Big-Ip 10200v-Ssl FirmwareAll versions
F5Big-Ip 12000 FirmwareAll versions
F5Big-Ip 5000s FirmwareAll versions
F5Big-Ip 5200v FirmwareAll versions
F5Big-Ip 5200v-Ssl FirmwareAll versions
F5Big-Ip 7000s FirmwareAll versions
F5Big-Ip 7200v FirmwareAll versions
F5Big-Ip 7200v-Ssl FirmwareAll versions
F5Big-Ip I10600 FirmwareAll versions
F5Big-Ip I10800 FirmwareAll versions
F5Big-Ip I11600 FirmwareAll versions
F5Big-Ip I11800 FirmwareAll versions
F5Big-Ip I15600 FirmwareAll versions
F5Big-Ip I15800 FirmwareAll versions
F5Big-Ip I5600 FirmwareAll versions
F5Big-Ip I5800 FirmwareAll versions
F5Big-Ip I7600 FirmwareAll versions
F5Big-Ip I7800 FirmwareAll versions
F5R10600 FirmwareAll versions
F5R10800 FirmwareAll versions
F5R10900 FirmwareAll versions
F5R5600 FirmwareAll versions
F5R5800 FirmwareAll versions
F5R5900 FirmwareAll versions
F5Velos Bx110 FirmwareAll versions
F5Viprion B2100 FirmwareAll versions
F5Viprion B2150 FirmwareAll versions
F5Viprion B2250 FirmwareAll versions
F5Viprion B4300 FirmwareAll versions
F5Viprion B4450 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-22839?
On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled, undisclosed requests cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
How severe is CVE-2023-22839?
CVE-2023-22839 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.63% probability of exploitation in the next 30 days.
How do I fix CVE-2023-22839?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-22839?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST