CVE-2022-28716Cross-site Scripting in F5 Big-ip

Severity
8.8HIGHNVD
CNA7.5
EPSS
1.2%
top 20.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 5
Latest updateMay 6

Description

On 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP AFM, CGNAT, and PEM Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluate

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

CVEListV5f5/big-ip16.1.x16.1.2.2+5
NVDf5/big-ip_carrier-grade_nat13.1.013.1.5+5
NVDf5/big-ip_advanced_firewall_manager13.1.013.1.5+5
NVDf5/big-ip_policy_enforcement_manager13.1.013.1.5+5

🔴Vulnerability Details

2
GHSA
GHSA-585h-3q27-j2jp: On 162022-05-06
CVEList
CVE-2022-28716: On 162022-05-05

📋Vendor Advisories

1
F5
CVE-2022-28716: On 162022-05-05
CVE-2022-28716 — Cross-site Scripting in F5 Big-ip | cvebase