PT-2022-15797 · F5 · Big-Ip Virtual Edition

Published

2022-01-25

·

Updated

2022-02-01

·

CVE-2022-23030

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions BIG-IP Virtual Edition (VE) versions 13.1.x BIG-IP Virtual Edition (VE) versions 14.1.x through 14.1.4.4 BIG-IP Virtual Edition (VE) versions 15.1.x through 15.1.4 BIG-IP Virtual Edition (VE) versions 16.1.x through 16.1.1
Description When the BIG-IP Virtual Edition (VE) uses the ixlv driver, which is used in SR-IOV mode and requires Intel X710/XL710/XXV710 family of network adapters on the Hypervisor, and TCP Segmentation Offload configuration is enabled, undisclosed requests may cause an increase in CPU resource utilization.
Recommendations For versions 13.1.x, consider disabling the ixlv driver or restricting its use until a patch is available. For versions 14.1.x through 14.1.4.4, consider disabling the ixlv driver or restricting its use until a patch is available. For versions 15.1.x through 15.1.4, consider disabling the ixlv driver or restricting its use until a patch is available. For versions 16.1.x through 16.1.1, consider disabling the ixlv driver or restricting its use until a patch is available.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23030

Affected Products

Big-Ip Virtual Edition