#VU71817 NULL pointer dereference in BIG-IP and BIG-IP DNS - CVE-2023-22839
Published: February 6, 2023
BIG-IP
BIG-IP DNS
F5 Networks
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dreference error when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled. A remote attacker can send specially crafted traffic to the device and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
According to vendor the following models are affected by this vulnerability:
- BIG-IP
- BIG-IP 5000 series (C109)
BIG-IP 7000 series (D110)
BIG-IP 10000 series (D113)
BIG-IP 12000 series (D111)
- BIG-IP 5000 series (C109)
- BIG-IP iSeries
- BIG-IP i5600, i5800 (C119)
BIG-IP i7600, i7800 (C118)
BIG-IP i10600, i10800 (C116)
BIG-IP i11600, i11800 (C123)
BIG-IP i15600, i15800 (D116)
- BIG-IP i5600, i5800 (C119)
- F5 rSeries
- r5000
- r10000
- F5 VELOS BX110 blade
- VIPRION B2100/2150 blade (A109, A113)
- VIPRION B2250 blade (A112)
- VIPRION B4300 series blade (A108, A110)
- VIPRION B4450 series blade