cbcvebase.
CVE-2022-41800
published 2022-12-07

CVE-2022-41800: In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode…

PriorityP184high8.7CVSS 3.1
AVNACLPRHUINSCCHIHAN
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
62.41%
99.1th percentile
In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected

68 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip
f5big-ip
f5big-ip
f5big-ip
f5big-ip
f5big-ip_aam
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager13.1.0 – 13.1.5
f5big-ip_access_policy_manager14.1.0 – 14.1.5
f5big-ip_access_policy_manager15.1.0 – 15.1.8
f5big-ip_access_policy_manager16.1.0 – 16.1.3
f5big-ip_advanced_firewall_manager13.1.0 – 17.0.0
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics
f5big-ip_analytics13.1.0 – 13.1.5
f5big-ip_analytics14.1.0 – 14.1.5
f5big-ip_analytics15.1.0 – 15.1.8
f5big-ip_analytics16.1.0 – 16.1.3
f5big-ip_apm
f5big-ip_application_acceleration_manager
f5big-ip_application_acceleration_manager13.1.0 – 13.1.5
f5big-ip_application_acceleration_manager14.1.0 – 14.1.5
f5big-ip_application_acceleration_manager15.1.0 – 15.1.8
f5big-ip_application_acceleration_manager16.1.0 – 16.1.3

Detection & IOCsextracted from sources · hover to see the quote

url/mgmt/shared/iapp/build-package
otherRUN_BUILD_RPM_TASK
othershared:iapp:build-package:buildrpmtaskstate
otherhttp.title:"big-ip®-+redirect" +"server"
  • Detect newline injection in the 'description' field of the RPM spec JSON payload — specifically look for %check section containing shell commands (e.g., bash reverse shell).
  • Alert on POST requests to /mgmt/shared/iapp/build-package following a request to /mgmt/shared/iapp/rpm-spec-creator — the two-step chain is the exploitation pattern.
  • Look for response bodies containing 'RUN_BUILD_RPM_TASK' or 'shared:iapp:build-package:buildrpmtaskstate' as indicators of successful exploitation trigger.
  • Successful exploitation results in remote code execution as the root user — monitor for unexpected outbound TCP connections from BIG-IP management interfaces.
  • Use Shodan query 'http.title:"big-ip®-+redirect" +"server"' or 'http.html:"big-ip apm"' to identify exposed BIG-IP management interfaces that may be targeted.
  • ·Vulnerability only applies to BIG-IP instances running in Appliance mode — standard mode deployments are not subject to the same security boundary bypass.
  • ·Exploitation requires authentication as an Administrator-role user — this is not an unauthenticated attack vector, unlike the related CVE-2022-1388.
  • ·Software versions that have reached End of Technical Support (EoTS) are not evaluated — affected versions span 13.1.0–17.0.0 across multiple BIG-IP product lines.

CVSS provenance

nvdv3.18.7HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
vulncheck8.7HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.