CVE-2022-23028

On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when global AFM SYN cookie protection (TCP Half Open flood vector) is activated in the AFM Device Dos or DOS profile, certain types of TCP connections will fail. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
Link Resource
https://support.f5.com/csp/article/K16101409 Mitigation Vendor Advisory
https://support.f5.com/csp/article/K16101409 Mitigation Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:47

Type Values Removed Values Added
References () https://support.f5.com/csp/article/K16101409 - Mitigation, Vendor Advisory () https://support.f5.com/csp/article/K16101409 - Mitigation, Vendor Advisory

Information

Published : 2022-01-25 20:15

Updated : 2024-11-21 06:47


NVD link : CVE-2022-23028

Mitre link : CVE-2022-23028

CVE.ORG link : CVE-2022-23028


JSON object : View

Products Affected

f5

  • big-ip_advanced_firewall_manager
CWE
CWE-682

Incorrect Calculation