« Back to list

CVE-2022-34844

Status: ModifiedHigh (7.5)—

In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP or BIG-IQ on Amazon Web Services (AWS) systems, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Successful exploitation relies on conditions outside of the attacker's control. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (12)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2022-34844",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "f5sirt@f5.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "f5sirt@f5.com",
      "affectedData": [
        {
          "vendor": "F5",
          "product": "BIG-IP",
          "versions": [
            {
              "status": "unaffected",
              "version": "13.1.0",
              "lessThan": "13.1.x*",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "14.1.0",
              "lessThan": "14.1.x*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "15.1.x",
              "lessThan": "15.1.6.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "16.1.x",
              "lessThan": "16.1.3.1",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "17.0.0",
              "lessThan": "17.0.x*",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "F5",
          "product": "BIG-IQ Centralized Management",
          "versions": [
            {
              "status": "unaffected",
              "version": "7.0.0",
              "lessThan": "7.x*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "8.0.0",
              "lessThan": "8.x*",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-08-04T18:15:10.180",
  "references": [
    {
      "url": "https://support.f5.com/csp/article/K34511555",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "f5sirt@f5.com"
    },
    {
      "url": "https://support.f5.com/csp/article/K34511555",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "f5sirt@f5.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP or BIG-IQ on Amazon Web Services (AWS) systems, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Successful exploitation relies on conditions outside of the attacker's control. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
    },
    {
      "lang": "es",
      "value": "En BIG-IP versiones 16.1.x anteriores a 16.1.3.1 y 15.1.x anteriores a 15.1.6.1, y en todas las versiones de BIG-IQ 8.x, cuando es usado el controlador Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) con BIG-IP o BIG-IQ en sistemas de Amazon Web Services (AWS), el tráfico no revelado puede causar la terminación del Traffic Management Microkernel (TMM). La explotación con éxito depende de condiciones fuera del control del atacante. Nota: Las versiones de software que han alcanzado el Fin del Soporte Técnico (EoTS) no son evaluadas no son evaluadas"
    }
  ],
  "lastModified": "2026-06-17T04:51:02.070",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "160570FB-7707-4362-90B0-F8C8FE8BA38B",
              "versionEndExcluding": "15.1.6.1",
              "versionStartIncluding": "15.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE0DB896-63DC-4622-A4DA-5B77A919EDF0",
              "versionEndExcluding": "16.1.3.1",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1FADD47D-1A4C-430F-B7C7-763F72893824",
              "versionEndExcluding": "15.1.6.1",
              "versionStartIncluding": "15.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE0CE38A-7167-4DE4-BB9D-CD6DF81FE0F2",
              "versionEndExcluding": "16.1.3.1",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2728406D-E27A-4434-BC3B-4D844F0E7BA0",
              "versionEndExcluding": "15.1.6.1",
              "versionStartIncluding": "15.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1BC32350-1D2B-4284-941B-8B98305C45F0",
              "versionEndExcluding": "16.1.3.1",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E7BD4CE-189E-4CA9-BE66-14A9CED7B63B",
              "versionEndExcluding": "15.1.6.1",
              "versionStartIncluding": "15.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83ACDEF1-CF4F-41BF-B256-EA7198BB9208",
              "versionEndExcluding": "16.1.3.1",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E51349F-E198-4643-A10D-6C1D35E10F0D",
              "versionEndExcluding": "15.1.6.1",
              "versionStartIncluding": "15.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "179FECCD-2795-4194-BED0-18CFEF792E9F",
              "versionEndExcluding": "16.1.3.1",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FDC0EE80-B537-4061-8D25-7BEE1A8191DE",
              "versionEndExcluding": "15.1.6.1",
              "versionStartIncluding": "15.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37684CEC-10C0-4B3C-B8F1-BBAAF3C08B61",
              "versionEndExcluding": "16.1.3.1",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E49DAA0-9716-4D3A-87D4-CE55E6480CE0",
              "versionEndExcluding": "15.1.6.1",
              "versionStartIncluding": "15.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58B1F7D1-80E2-4C5E-967C-C48244BA7B43",
              "versionEndExcluding": "16.1.3.1",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C92185E0-F49B-41E2-815C-93C5643C2CAA",
              "versionEndExcluding": "15.1.6.1",
              "versionStartIncluding": "15.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4FE45D7A-BBB1-41AB-B980-B0BE9A3B5E83",
              "versionEndExcluding": "16.1.3.1",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC49DC01-B0B5-41DF-8B8B-CCE0AED8748C",
              "versionEndExcluding": "15.1.6.1",
              "versionStartIncluding": "15.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6A57376D-044D-46E4-9702-ECEF1F8A6380",
              "versionEndExcluding": "16.1.3.1",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0E7A929-53FF-482D-9935-E3B2E6C9D174",
              "versionEndExcluding": "15.1.6.1",
              "versionStartIncluding": "15.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "330DF580-A2F8-43A9-A73A-18DAE744352A",
              "versionEndExcluding": "16.1.3.1",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4DCF4D67-ECC3-4808-AF91-CA2BE17E5E8D",
              "versionEndExcluding": "15.1.6.1",
              "versionStartIncluding": "15.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EA2E069B-1FD5-48BE-9468-9C70C2BC30C1",
              "versionEndExcluding": "16.1.3.1",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-iq_centralized_management:7.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B589C35-55F2-4D40-B5A6-8267EE20D627"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-iq_centralized_management:7.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DA0B396A-B5CE-4337-A33A-EF58C4589CB3"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-iq_centralized_management:8.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "756F8EDF-6F87-4C6D-B2DB-ED97F799C27F"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-iq_centralized_management:8.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "99D94840-8F62-4232-89F0-A83313AD418A"
            },
            {
              "criteria": "cpe:2.3:a:f5:big-iq_centralized_management:8.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1316A43D-B002-4D27-A89B-63C6F827B722"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "f5sirt@f5.com"
}