CVE-2022-23031
published 2022-01-25CVE-2022-23031: On BIG-IP FPS, ASM, and Advanced WAF versions 16.1.x before 16.1.1, 15.1.x before 15.1.4, and 14.1.x before 14.1.4.4, an XML External Entity (XXE)…
PriorityP427medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.83%
53.6th percentile
On BIG-IP FPS, ASM, and Advanced WAF versions 16.1.x before 16.1.1, 15.1.x before 15.1.4, and 14.1.x before 14.1.4.4, an XML External Entity (XXE) vulnerability exists in an undisclosed page of the F5 Advanced Web Application Firewall (Advanced WAF) and BIG-IP ASM Traffic Management User Interface (TMUI), also referred to as the Configuration utility, that allows an authenticated high-privileged attacker to read local files and force BIG-IP to send HTTP requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_advanced_waf | — | — |
| f5 | big-ip_advanced_web_application_firewall | 14.1.0 – 14.1.4 | — |
| f5 | big-ip_advanced_web_application_firewall | 15.1.0 – 15.1.3 | — |
| f5 | big-ip_advanced_web_application_firewall | 16.0.0 – 16.1.0 | — |
| f5 | big-ip_application_security_manager | 14.1.0 – 14.1.4 | — |
| f5 | big-ip_application_security_manager | 15.1.0 – 15.1.3 | — |
| f5 | big-ip_application_security_manager | 16.0.0 – 16.1.0 | — |
| f5 | big-ip_asm | — | — |
| f5 | big-ip_fps | — | — |
| f5 | big-ip_fraud_protection_service | 14.1.0 – 14.1.4 | — |
| f5 | big-ip_fraud_protection_service | 15.1.0 – 15.1.3 | — |
| f5 | big-ip_fraud_protection_service | 16.0.0 – 16.1.0 | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2022-23031: On BIG-IP FPS, ASM, and Advanced WAF versions 16
vendor_f5·2022-01-25·CVSS 4.9
CVE-2022-23031 [MEDIUM] CWE-611 CVE-2022-23031: On BIG-IP FPS, ASM, and Advanced WAF versions 16
CVE-2022-23031: On BIG-IP FPS, ASM, and Advanced WAF versions 16
On BIG-IP FPS, ASM, and Advanced WAF versions 16.1.x before 16.1.1, 15.1.x before 15.1.4, and 14.1.x before 14.1.4.4, an XML External Entity (XXE) vulnerability exists in an undisclosed page of the F5 Advanced Web Application Firewall (Advanced WAF) and BIG-IP ASM Traffic Management User Interface (TMUI), also referred to as the Configuration utility, that allows an authenticated high-privileged attacker to read local files and force BIG-IP to send HTTP requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: BIG-IP ASM, BIG-IP Advanced WAF, BIG-IP FPS
Affected Versions: 14.1.0 - 14.1.4; 15.1.0 - 15.1.3; 16.0.0 - 16.1.0
F5 Advisory Articles: K61112120
F5 Refe
GHSA
GHSA-6j94-pvhj-7f99: On BIG-IP FPS, ASM, and Advanced WAF versions 16
ghsa_unreviewed·2022-01-26
CVE-2022-23031 [MEDIUM] CWE-611 GHSA-6j94-pvhj-7f99: On BIG-IP FPS, ASM, and Advanced WAF versions 16
On BIG-IP FPS, ASM, and Advanced WAF versions 16.1.x before 16.1.1, 15.1.x before 15.1.4, and 14.1.x before 14.1.4.4, an XML External Entity (XXE) vulnerability exists in an undisclosed page of the F5 Advanced Web Application Firewall (Advanced WAF) and BIG-IP ASM Traffic Management User Interface (TMUI), also referred to as the Configuration utility, that allows an authenticated high-privileged attacker to read local files and force BIG-IP to send HTTP requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-01-25
Published