Denial of service in BIG-IP DNS with Rapid Response mode enabled



Published: 2023-02-06
Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2023-22839
CWE-ID CWE-476
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
BIG-IP
Hardware solutions / Firmware

BIG-IP DNS
Hardware solutions / Routers & switches, VoIP, GSM, etc

Vendor F5 Networks

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) NULL pointer dereference

EUVDB-ID: #VU71817

Risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-22839

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dreference error when  a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled. A remote attacker can send specially crafted traffic to the device and perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

According to vendor the following models are affected by this vulnerability:

  • BIG-IP
    • BIG-IP 5000 series (C109)
      BIG-IP 7000 series (D110)
      BIG-IP 10000 series (D113)
      BIG-IP 12000 series (D111)
  • BIG-IP iSeries
    • BIG-IP i5600, i5800 (C119)
      BIG-IP i7600, i7800 (C118)
      BIG-IP i10600, i10800 (C116)
      BIG-IP i11600, i11800 (C123)
      BIG-IP i15600, i15800 (D116)
  • F5 rSeries
    • r5000
    • r10000
  • F5 VELOS BX110 blade
  • VIPRION B2100/2150 blade (A109, A113)
  • VIPRION B2250 blade (A112)
  • VIPRION B4300 series blade (A108, A110)
  • VIPRION B4450 series blade

Vulnerable software versions

BIG-IP: 14.1.0 - 17.0.0.1

BIG-IP DNS: 14.1.0 - 17.0.0.1

External links

http://my.f5.com/manage/s/article/K37708118


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###