BIG-IP Virtual Edition 15.1.4-15.1.7 & 14.1.5-14.1.5.2 Crash via FastL4 TMM DoS
CVE-2023-23555 Published on February 1, 2023

BIG-IP Virtual Edition vulnerability
On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 and 14.1.x beginning in 14.1.5 to before 14.1.5.3, and BIG-IP SPK beginning in 1.5.0 to before 1.6.0, when FastL4 profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

NVD

Vulnerability Analysis

CVE-2023-23555 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
NONE
Availability Impact:
HIGH

Weakness Type

Improper Initialization

The software does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used. This can have security implications when the associated resource is expected to have certain properties or values, such as a variable that determines whether a user has been authenticated or not.


Products Associated with CVE-2023-23555

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2023-23555 are published in these products:

 
 
 
 
 
 
 
 
 
 
 
 
 
 

Affected Versions

F5 BIG-IP: F5 BIG-IP SPK:

Exploit Probability

EPSS
0.89%
Percentile
75.20%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.