« Volver al listado

CVE-2022-23020

Estado: ModificadaAlta (7.5)—

On BIG-IP version 16.1.x before 16.1.2, when the 'Respond on Error' setting is enabled on the Request Logging profile and configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (11)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-23020",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.1,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "f5sirt@f5.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "BIG-IP",
          "versions": [
            {
              "status": "affected",
              "version": "16.1.x before 16.1.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-01-25T20:15:09.530",
  "references": [
    {
      "url": "https://support.f5.com/csp/article/K17514331",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "f5sirt@f5.com"
    },
    {
      "url": "https://support.f5.com/csp/article/K17514331",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "f5sirt@f5.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "On BIG-IP version 16.1.x before 16.1.2, when the 'Respond on Error' setting is enabled on the Request Logging profile and configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
    },
    {
      "lang": "es",
      "value": "En BIG-IP versiones 16.1.x anteriores a 16.1.2, cuando el ajuste \"Respond on Error\" está habilitado en el perfil de registro de peticiones y configurado en un servidor virtual, las peticiones no reveladas pueden causar una terminación del Microkernel de Administración del Tráfico (TMM). Nota: Las versiones de software que han alcanzado el Fin de Soporte Técnico (EoTS) no son evaluadas"
    }
  ],
  "lastModified": "2026-06-17T04:29:21.700",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A84B00F-DE07-4310-911D-C491C5B6C4DE",
              "versionEndExcluding": "16.1.2",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9779C2D-22DD-49E4-AA94-DD6FBF8B5F61",
              "versionEndExcluding": "16.1.2",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "623D635A-A7B3-4C98-A8D6-49692B2B1D81",
              "versionEndExcluding": "16.1.2",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D8983C6-DE4E-43D3-A9B5-64691F6AF3D7",
              "versionEndExcluding": "16.1.2",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1BC228C7-FDF9-4D55-A82A-F055414733A8",
              "versionEndExcluding": "16.1.2",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1C2F08B4-BE3D-45F0-8581-D4B3A5487F6A",
              "versionEndExcluding": "16.1.2",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9219C213-C577-4560-9145-538734FF270C",
              "versionEndExcluding": "16.1.2",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "000B88C9-BEC5-40A0-B4A3-547825D92E83",
              "versionEndExcluding": "16.1.2",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E94B5FC-B1F4-4566-B058-9AEBC8960BAF",
              "versionEndExcluding": "16.1.2",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4661893C-022F-4B17-8DE9-62252E54995C",
              "versionEndExcluding": "16.1.2",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20EB82E2-925F-4843-9A3C-A46D023A177D",
              "versionEndExcluding": "16.1.2",
              "versionStartIncluding": "16.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "f5sirt@f5.com"
}