F5 BIG-IP Service Proxy (SPK) 1.6.0 for Kubernetes

CPE Details

F5 BIG-IP Service Proxy (SPK) 1.6.0 for Kubernetes
1.6.0
2023-02-08
19h03 +00:00
2023-02-16
15h12 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:f5:big-ip_service_proxy:1.6.0:*:*:*:*:kubernetes:*:*

Informations

Vendor

f5

Product

big-ip_service_proxy

Version

1.6.0

Target Software

kubernetes

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-22664 2023-02-01 17h56 +00:00 On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
7.5
High
CVE-2002-20001 2021-11-11 00h00 +00:00 The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.
7.5
High