CVE-2022-41800
published 2022-12-07CVE-2022-41800: In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode…
PriorityP184high8.7CVSS 3.1
AVNACLPRHUINSCCHIHAN
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
62.41%
99.1th percentile
In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
68 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | — | — |
| f5 | big-ip | — | — |
| f5 | big-ip | — | — |
| f5 | big-ip | — | — |
| f5 | big-ip | — | — |
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | 13.1.0 – 13.1.5 | — |
| f5 | big-ip_access_policy_manager | 14.1.0 – 14.1.5 | — |
| f5 | big-ip_access_policy_manager | 15.1.0 – 15.1.8 | — |
| f5 | big-ip_access_policy_manager | 16.1.0 – 16.1.3 | — |
| f5 | big-ip_advanced_firewall_manager | 13.1.0 – 17.0.0 | — |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 13.1.0 – 13.1.5 | — |
| f5 | big-ip_analytics | 14.1.0 – 14.1.5 | — |
| f5 | big-ip_analytics | 15.1.0 – 15.1.8 | — |
| f5 | big-ip_analytics | 16.1.0 – 16.1.3 | — |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | 13.1.0 – 13.1.5 | — |
| f5 | big-ip_application_acceleration_manager | 14.1.0 – 14.1.5 | — |
| f5 | big-ip_application_acceleration_manager | 15.1.0 – 15.1.8 | — |
| f5 | big-ip_application_acceleration_manager | 16.1.0 – 16.1.3 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect newline injection in the 'description' field of the RPM spec JSON payload — specifically look for %check section containing shell commands (e.g., bash reverse shell). ↗
- →Alert on POST requests to /mgmt/shared/iapp/build-package following a request to /mgmt/shared/iapp/rpm-spec-creator — the two-step chain is the exploitation pattern. ↗
- →Look for response bodies containing 'RUN_BUILD_RPM_TASK' or 'shared:iapp:build-package:buildrpmtaskstate' as indicators of successful exploitation trigger. ↗
- →Successful exploitation results in remote code execution as the root user — monitor for unexpected outbound TCP connections from BIG-IP management interfaces. ↗
- →Use Shodan query 'http.title:"big-ip®-+redirect" +"server"' or 'http.html:"big-ip apm"' to identify exposed BIG-IP management interfaces that may be targeted. ↗
- ·Vulnerability only applies to BIG-IP instances running in Appliance mode — standard mode deployments are not subject to the same security boundary bypass. ↗
- ·Exploitation requires authentication as an Administrator-role user — this is not an unauthenticated attack vector, unlike the related CVE-2022-1388. ↗
- ·Software versions that have reached End of Technical Support (EoTS) are not evaluated — affected versions span 13.1.0–17.0.0 across multiple BIG-IP product lines. ↗
CVSS provenance
nvdv3.18.7HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
vulncheck8.7HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2022-41800: In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may ...
vendor_f5·2022-12-07·CVSS 8.7
CVE-2022-41800 [HIGH] CWE-77 CVE-2022-41800: In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may ...
CVE-2022-41800: In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may ...
In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Analytics, BIG-IP DNS, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, iControl REST
Affected Versions: 13.1.0 - 13.1.5; 13.1.0 - 17.0.0; 14.1.0 - 14.1.5; 15.1.0 - 15.1.8; 16.1.0
GHSA
GHSA-cqcj-7vqr-p254: In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode
ghsa_unreviewed·2022-12-07
CVE-2022-41800 [HIGH] CWE-77 GHSA-cqcj-7vqr-p254: In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode
In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
VulnCheck
F5 big-ip_access_policy_manager Improper Neutralization of Special Elements used in a Command ('Command Injection')
vulncheck·2022·CVSS 8.7
CVE-2022-41800 [HIGH] F5 big-ip_access_policy_manager Improper Neutralization of Special Elements used in a Command ('Command Injection')
F5 big-ip_access_policy_manager Improper Neutralization of Special Elements used in a Command ('Command Injection')
In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected: F5 big-ip_access_policy_manager
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.labs.greynoise.io/grimoire/2023-12-14-if-youre-going-to-spray-m
No detection rules found.
Metasploit
F5 BIG-IP iControl Authenticated RCE via RPM Creator
metasploit
F5 BIG-IP iControl Authenticated RCE via RPM Creator
F5 BIG-IP iControl Authenticated RCE via RPM Creator
This module exploits a newline injection into an RPM .rpmspec file that permits authenticated users to remotely execute commands. Successful exploitation results in remote code execution as the root user.
Nuclei
F5 BIG-IP Appliance Mode - Command Injection
nuclei·CVSS 9.8
CVE-2022-41800 [CRITICAL] F5 BIG-IP Appliance Mode - Command Injection
F5 BIG-IP Appliance Mode - Command Injection
When running in Appliance mode, an authenticated user assigned the Administrator role may bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint.
Template:
id: CVE-2022-41800
info:
name: F5 BIG-IP Appliance Mode - Command Injection
author: dwisiswant0
severity: high
description: |
When running in Appliance mode, an authenticated user assigned the Administrator role may bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint.
remediation: |
Apply security patches from F5 Networks as outlined in K97843387 and ensure Appliance mode restrictions are properly enforced.
impact: |
A successful exploit can allow the attacker to execute remote commands on server using authorization bypass (CVE-
Greynoiseio
Cybersecurity in the Age of AI: What Experts are Saying
blogs_greynoiseio·2024-05-28
Cybersecurity in the Age of AI: What Experts are Saying
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
Mining The Undiscovered Country With GreyNoise EAP Sensors: F5 BIG-IP Edition
blogs_greynoiseio·CVSS 9.8
[CRITICAL] Mining The Undiscovered Country With GreyNoise EAP Sensors: F5 BIG-IP Edition
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
The Confusing History of F5 BIG-IP RCE Vulnerabilities
blogs_greynoiseio·CVSS 9.8
[CRITICAL] The Confusing History of F5 BIG-IP RCE Vulnerabilities
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
2022-12-07
Published
Exploited in the wild