PT-2022-17690 · F5 · F5 Big-Ip
Published
2022-05-05
·
Updated
2022-05-16
·
CVE-2022-26130
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP versions 13.1.x prior to 13.1.5
F5 BIG-IP versions 14.1.x prior to 14.1.4.6
F5 BIG-IP versions 15.1.x prior to 15.1.5.1
F5 BIG-IP versions 16.1.x prior to 16.1.2.2
Description
When an Active mode-enabled FTP profile is configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing active FTP data channel connections.
Recommendations
For F5 BIG-IP versions 13.1.x prior to 13.1.5, update to version 13.1.5 or later.
For F5 BIG-IP versions 14.1.x prior to 14.1.4.6, update to version 14.1.4.6 or later.
For F5 BIG-IP versions 15.1.x prior to 15.1.5.1, update to version 15.1.5.1 or later.
For F5 BIG-IP versions 16.1.x prior to 16.1.2.2, update to version 16.1.2.2 or later.
Fix
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
F5 Big-Ip