LOW · 3.7

CVE-2022-41983

On specific hardware platforms, on BIG-IP versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, while Intel QAT (QuickAssist Technology) and the AE...

Vulnerability Description

On specific hardware platforms, on BIG-IP versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, while Intel QAT (QuickAssist Technology) and the AES-GCM/CCM cipher is in use, undisclosed conditions can cause BIG-IP to send data unencrypted even with an SSL Profile applied.

CVSS Score

3.7

LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
F5Big-Ip Access Policy Manager>= 13.1.0, <= 13.1.5
F5Big-Ip Advanced Firewall Manager>= 13.1.0, <= 13.1.5
F5Big-Ip Advanced Web Application Firewall>= 13.1.0, <= 13.1.5
F5Big-Ip Analytics>= 13.1.0, <= 13.1.5
F5Big-Ip Application Acceleration Manager>= 13.1.0, <= 13.1.5
F5Big-Ip Application Security Manager>= 13.1.0, <= 13.1.5
F5Big-Ip Application Visibility And Reporting>= 13.1.0, <= 13.1.5
F5Big-Ip Carrier-Grade Nat>= 13.1.0, <= 13.1.5
F5Big-Ip Ddos Hybrid Defender>= 13.1.0, <= 13.1.5
F5Big-Ip Domain Name System>= 13.1.0, <= 13.1.5
F5Big-Ip Edge Gateway>= 13.1.0, <= 13.1.5
F5Big-Ip Fraud Protection Service>= 13.1.0, <= 13.1.5
F5Big-Ip Global Traffic Manager>= 13.1.0, <= 13.1.5
F5Big-Ip Link Controller>= 13.1.0, <= 13.1.5
F5Big-Ip Local Traffic Manager>= 13.1.0, <= 13.1.5
F5Big-Ip Policy Enforcement Manager>= 13.1.0, <= 13.1.5
F5Big-Ip Ssl Orchestrator>= 13.1.0, <= 13.1.5
F5Big-Ip Webaccelerator>= 13.1.0, <= 13.1.5
F5Big-Ip Websafe>= 13.1.0, <= 13.1.5

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-41983?

CVE-2022-41983 is a vulnerability with a CVSS score of 3.7 (LOW). On specific hardware platforms, on BIG-IP versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, while Intel QAT (QuickAssist Technology) and the AE...

How severe is CVE-2022-41983?

CVE-2022-41983 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-41983?

Check the references section above for vendor advisories and patch information. Affected products include: F5 Big-Ip Access Policy Manager, F5 Big-Ip Advanced Firewall Manager, F5 Big-Ip Advanced Web Application Firewall, F5 Big-Ip Analytics, F5 Big-Ip Application Acceleration Manager.