CVE-2022-23032

CWE-3464 documents4 sources
Severity
5.3MEDIUM
EPSS
0.1%
top 68.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 25
Latest updateJan 26

Description

In all versions before 7.2.1.4, when proxy settings are configured in the network access resource of a BIG-IP APM system, connecting BIG-IP Edge Client on Mac and Windows is vulnerable to a DNS rebinding attack. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

CVEListV5big-ip_edge_client_for_mac_and_windowsAll versions before 7.2.1.4
NVDf5/big-ip_access_policy_manager11.6.111.6.5+5

🔴Vulnerability Details

2
GHSA
GHSA-m6rx-82hw-rv4g: In all versions before 72022-01-26
CVEList
CVE-2022-23032: In all versions before 72022-01-25

📋Vendor Advisories

1
F5
CVE-2022-23032: In all versions before 72022-01-25
CVE-2022-23032 (MEDIUM CVSS 5.3) | In all versions before 7.2.1.4 | cvebase.io