When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact:
System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the BIG-IP system.
There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 8
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
F5 Big-Ip_Next_Cloud-Native_Network_Functions
cpe:2.3:a:f5:big-ip_next_cloud-native_network_functions:*:*:*:*:*:*:*:*
|
1.1.0
|
1.4.3
|
|
F5 Big-Ip_Next_Cloud-Native_Network_Functions
cpe:2.3:a:f5:big-ip_next_cloud-native_network_functions:*:*:*:*:*:*:*:*
|
2.0.0
|
2.2.3
|
|
F5 Big-Ip_Next_Cloud-Native_Network_Functions
cpe:2.3:a:f5:big-ip_next_cloud-native_network_functions:2.3.0:*:*:*:*:*:*:*
|
— | — |
|
F5 Big-Ip_Next_For_Kubernetes
cpe:2.3:a:f5:big-ip_next_for_kubernetes:*:*:*:*:*:*:*:*
|
2.0.0
|
2.2.3
|
|
F5 Big-Ip_Next_For_Kubernetes
cpe:2.3:a:f5:big-ip_next_for_kubernetes:2.3.0:*:*:*:*:*:*:*
|
— | — |
|
F5 Big-Ip_Next_Service_Proxy_For_Kubernetes
cpe:2.3:a:f5:big-ip_next_service_proxy_for_kubernetes:*:*:*:*:*:*:*:*
|
1.7.0
|
1.7.18
|
|
F5 Big-Ip_Next_Service_Proxy_For_Kubernetes
cpe:2.3:a:f5:big-ip_next_service_proxy_for_kubernetes:*:*:*:*:*:*:*:*
|
1.8.0
|
<= 1.9.2
|
|
F5 Big-Ip_Next_Service_Proxy_For_Kubernetes
cpe:2.3:a:f5:big-ip_next_service_proxy_for_kubernetes:*:*:*:*:*:*:*:*
|
2.0.0
|
<= 2.0.3
|