Buffer overflow in BIG-IP - CVE-2023-22422
Published: February 6, 2023
BIG-IP
F5 Networks
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation when an HTTP profile with the non-default Enforcement options Enforce RFC Compliance and Unknown Methods: Reject are configured on a virtual server. A remote attacker can send specially crafted traffic to the affected device, trigger a buffer overflow and crash the TMM process.