In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.5.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, using an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
Link | Resource |
---|---|
https://support.f5.com/csp/article/K11010341 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
10 Aug 2022, 19:11
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
References | (MISC) https://support.f5.com/csp/article/K11010341 - Vendor Advisory | |
First Time |
F5
F5 big-ip Link Controller F5 big-ip Application Security Manager F5 big-ip Fraud Protection Service F5 big-ip Domain Name System F5 big-ip Application Acceleration Manager F5 big-ip Access Policy Manager F5 big-ip Analytics F5 big-ip Policy Enforcement Manager F5 big-ip Local Traffic Manager F5 big-ip Advanced Firewall Manager F5 big-ip Global Traffic Manager |
|
CPE | cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* |
04 Aug 2022, 18:34
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-08-04 18:15
Updated : 2023-12-10 14:35
NVD link : CVE-2022-35243
Mitre link : CVE-2022-35243
CVE.ORG link : CVE-2022-35243
JSON object : View
Products Affected
f5
- big-ip_analytics
- big-ip_access_policy_manager
- big-ip_fraud_protection_service
- big-ip_application_security_manager
- big-ip_local_traffic_manager
- big-ip_advanced_firewall_manager
- big-ip_application_acceleration_manager
- big-ip_domain_name_system
- big-ip_link_controller
- big-ip_policy_enforcement_manager
- big-ip_global_traffic_manager
CWE
CWE-269
Improper Privilege Management