F5 BIG-IP Next SPK
cpe:2.3:a:f5:big-ip_next:*:*:*:*:*:*:*
- 2.0.0
- ~2.0
- ~1.7.0, <= 1.7.14
A denial-of-service vulnerability has been identified in F5 BIG-IP Next products (CNF, SPK, and Kubernetes) when HTTP/2 Ingress is configured. Undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate, disrupting service as the TMM process restarts. This issue allows a remote, unauthenticated attacker to cause a DoS on the BIG-IP system, affecting only the data plane.
Exploitation of this vulnerability disrupts traffic by causing the TMM process to terminate and restart, leading to a temporary denial-of-service condition on the BIG-IP system.
F5 has released an engineering hotfix for this vulnerability, available through the MyF5 Downloads page. For more information about the hotfix policy, refer to the F5 critical issue hotfix policy article.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.