CVE-2023-22341 is a denial-of-service vulnerability affecting F5 BIG-IP Access Policy Manager (APM) versions 14.1.x before 14.1.5.3 and all versions of 13.1.x. Specifically, when an APM system is configured with an OAuth Server referencing an OAuth Provider, an OAuth profile with the Authorization Endpoint set to '/', and an access profile linked to this OAuth profile and an HTTPS virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This vulnerability carries a CVSSv3.1 score of 7.5 (High), indicating a network-based attack with low complexity that does not require user interaction or privileges, leading to high availability impact (denial of service). The EPSS score is low at 0.01037, suggesting a low probability of exploitation in the wild. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for the majority of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.1.0, <= 13.1.5CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* | ||
>= 14.1.0, < 14.1.5.3CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* | ||
>= 14.1.0, < 14.1.5.3CPE match | cpe:2.3:a:f5:big-ip:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.