cbcvebase.
CVE-2022-41800
published 2022-12-07

CVE-2022-41800: In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode…

high8.7CVSS 3.1
AVNACLPRHUINSCCHIHAN
EXPLOIT
In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected

68 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip
f5big-ip
f5big-ip
f5big-ip
f5big-ip
f5big-ip_aam
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager13.1.0 – 13.1.5
f5big-ip_access_policy_manager14.1.0 – 14.1.5
f5big-ip_access_policy_manager15.1.0 – 15.1.8
f5big-ip_access_policy_manager16.1.0 – 16.1.3
f5big-ip_advanced_firewall_manager13.1.0 – 17.0.0
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics
f5big-ip_analytics13.1.0 – 13.1.5
f5big-ip_analytics14.1.0 – 14.1.5
f5big-ip_analytics15.1.0 – 15.1.8
f5big-ip_analytics16.1.0 – 16.1.3
f5big-ip_apm
f5big-ip_application_acceleration_manager
f5big-ip_application_acceleration_manager13.1.0 – 13.1.5
f5big-ip_application_acceleration_manager14.1.0 – 14.1.5
f5big-ip_application_acceleration_manager15.1.0 – 15.1.8
f5big-ip_application_acceleration_manager16.1.0 – 16.1.3

CVSS provenance

nvdv3.18.7HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
vulncheck8.7HIGH