In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
Link | Resource |
---|---|
https://support.f5.com/csp/article/K13325942 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
07 Nov 2023, 03:53
Type | Values Removed | Values Added |
---|---|---|
Summary | In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
12 Dec 2022, 15:25
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:f5:big-ip_domain_name_system:17.0.0:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_policy_enforcement_manager:17.0.0:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_access_policy_manager:17.0.0:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_local_traffic_manager:17.0.0:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_global_traffic_manager:17.0.0:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_link_controller:17.0.0:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_application_acceleration_manager:17.0.0:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_application_security_manager:17.0.0:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_analytics:17.0.0:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:* cpe:2.3:a:f5:big-ip_fraud_protection_service:17.0.0:*:*:*:*:*:*:* |
|
References | (MISC) https://support.f5.com/csp/article/K13325942 - Vendor Advisory | |
CWE | CWE-77 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.7 |
First Time |
F5 big-ip Link Controller
F5 big-ip Advanced Firewall Manager F5 big-ip Policy Enforcement Manager F5 big-ip Global Traffic Manager F5 big-ip Domain Name System F5 big-ip Access Policy Manager F5 F5 big-ip Local Traffic Manager F5 big-ip Application Security Manager F5 big-ip Analytics F5 big-ip Application Acceleration Manager F5 big-ip Fraud Protection Service |
07 Dec 2022, 04:52
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-12-07 04:15
Updated : 2023-12-10 14:48
NVD link : CVE-2022-41800
Mitre link : CVE-2022-41800
CVE.ORG link : CVE-2022-41800
JSON object : View
Products Affected
f5
- big-ip_analytics
- big-ip_access_policy_manager
- big-ip_fraud_protection_service
- big-ip_application_security_manager
- big-ip_local_traffic_manager
- big-ip_advanced_firewall_manager
- big-ip_application_acceleration_manager
- big-ip_domain_name_system
- big-ip_link_controller
- big-ip_policy_enforcement_manager
- big-ip_global_traffic_manager
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')