CVE-2022-35735Injection in F5 Big-ip Access Policy Manager

CWE-74Injection4 documents4 sources
Severity
7.2HIGHNVD
EPSS
1.6%
top 18.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 4
Latest updateAug 5

Description

In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, an authenticated attacker with Resource Administrator or Manager privileges can create or modify existing monitor objects in the Configuration utility in an undisclosed manner leading to a privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages12 packages

NVDf5/big-ip_access_policy_manager14.1.014.1.5.1+3
NVDf5/big-ip_local_traffic_manager14.1.014.1.5.1+3
NVDf5/big-ip_global_traffic_manager14.1.014.1.5.1+3
NVDf5/big-ip_advanced_firewall_manager14.1.014.1.5.1+3
NVDf5/big-ip_policy_enforcement_manager14.1.014.1.5.1+3

🔴Vulnerability Details

2
GHSA
GHSA-mxp9-7gv4-vp7j: In BIG-IP Versions 162022-08-05
CVEList
BIG-IP monitor configuration vulnerability CVE-2022-357352022-08-04

📋Vendor Advisories

1
F5
CVE-2022-35735: In BIG-IP Versions 162022-08-04
CVE-2022-35735 — Injection in F5 | cvebase