ZeroHour

CVE-2022-34865

CVSS 3.1
9.1 critical
EPSS
<1%p36
Published
()
Modified
Description

In BIG-IP Versions 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, Traffic Intelligence feeds, which use HTTPS, do not verify the remote endpoint identity, allowing for potential data poisoning. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vendors
f5
Products
big-ip access policy manager, big-ip advanced firewall manager, big-ip analytics, big-ip application acceleration manager, big-ip application security manager, big-ip domain name system, big-ip fraud protection service, big-ip global traffic manager, big-ip link controller, big-ip local traffic manager, big-ip policy enforcement manager
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.