Site icon API Security Blog

BIG-IP iRules vulnerability CVE-2022-41624

When a sideband iRule is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. ([CVE-2022-41624]())

Impact

System performance can degrade until the Traffic Management Microkernel (TMM) process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a resource consumption type denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only.

For more information, refer to [Sideband iRules]() on F5 CloudDocs.Read More

Exit mobile version