Unknown
CVE-2023-22839
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2023-22839
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled, undisclosed requests cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
- f5
Products
- big-ip 10000s firmware -,
- big-ip 10200v firmware -,
- big-ip 10200v-ssl firmware -,
- big-ip 12000 firmware -,
- big-ip 5000s firmware -,
- big-ip 5200v firmware -,
- big-ip 5200v-ssl firmware -,
- big-ip 7000s firmware -,
- big-ip 7200v firmware -,
- big-ip 7200v-ssl firmware -,
- big-ip domain name system,
- big-ip i10600 firmware -,
- big-ip i10800 firmware -,
- big-ip i11600 firmware -,
- big-ip i11800 firmware -,
- big-ip i15600 firmware -,
- big-ip i15800 firmware -,
- big-ip i5600 firmware -,
- big-ip i5800 firmware -,
- big-ip i7600 firmware -,
- big-ip i7800 firmware -,
- big-ip local traffic manager,
- r10600 firmware -,
- r10800 firmware -,
- r10900 firmware -,
- r5600 firmware -,
- r5800 firmware -,
- r5900 firmware -,
- velos bx110 firmware -,
- viprion b2100 firmware -,
- viprion b2150 firmware -,
- viprion b2250 firmware -,
- viprion b4300 firmware -,
- viprion b4450 firmware -
References
Miscellaneous
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: