
Cloud Vulnerability DB
A community-led vulnerabilities database
A denial of service (DoS) vulnerability was discovered in F5 BIG-IP versions 14.1.0-14.1.2.3. The vulnerability occurs when undisclosed requests are sent to BIG-IP HTTP/2 virtual servers, particularly when ciphers that have been blacklisted by the HTTP/2 RFC are used on backend servers. This is specifically a data-plane issue with no control-plane exposure (CVE Mitre, NVD).
The vulnerability affects BIG-IP versions 14.1.0 through 14.1.2.3. The issue specifically involves the HTTP/2 virtual servers and their interaction with blacklisted ciphers as defined in the HTTP/2 RFC. The vulnerability is limited to the data-plane, meaning it affects traffic processing rather than device management functions (CVE Mitre).
When successfully exploited, this vulnerability can lead to a denial of service condition on affected BIG-IP systems, potentially disrupting the availability of services running on HTTP/2 virtual servers (NVD).
The vulnerability can be triggered by sending specific undisclosed requests to BIG-IP HTTP/2 virtual servers when certain blacklisted ciphers are in use on backend servers (CVE Mitre).
The vulnerability has been addressed in versions after 14.1.2.3. Organizations running affected versions should upgrade to a patched version to mitigate this vulnerability (CERT-FR).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."