CVE-2022-41617Command Injection in F5 Big-ip Advanced WAF ASM

CWE-77Command Injection4 documents4 sources
Severity
7.2HIGHNVD
EPSS
4.4%
top 10.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 19
Latest updateOct 20

Description

In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, When the Advanced WAF / ASM module is provisioned, an authenticated remote code execution vulnerability exists in the BIG-IP iControl REST interface.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages3 packages

CVEListV5f5/big-ip_advanced_waf_asm16.1.x16.1.3.1+3
NVDf5/big-ip_application_security_manager13.1.013.1.5.1+3

🔴Vulnerability Details

2
GHSA
GHSA-fc4r-fxrx-hcf5: In versions 162022-10-20
CVEList
BIG-IP Advanced WAF and ASM iControl REST vulnerability CVE-2022-416172022-10-19

📋Vendor Advisories

1
F5
CVE-2022-41617: In versions 162022-10-19
CVE-2022-41617 — Command Injection in F5 | cvebase