cbcvebase.
CVE-2023-22374
published 2023-02-01

CVE-2023-22374: A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute…

PriorityP270high8.5CVSS 3.1
AVNACHPRLUINSCCHIHAH
EPSS
72.65%
99.4th percentile
A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appliance mode BIG-IP, a successful exploit of this vulnerability can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected

74 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip>= 13.1.5 < **
f5big-ip>= 14.1.4.6 < 14.1.5.414.1.5.4
f5big-ip>= 15.1.5.1 < 15.1.8.215.1.8.2
f5big-ip>= 16.1.2.2 < 16.1.3.416.1.3.4
f5big-ip>= 17.0.0 < 17.1.017.1.0
f5big-ip_aam
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager14.1.4.6 – 14.1.5
f5big-ip_access_policy_manager15.1.5.1 – 15.1.8
f5big-ip_access_policy_manager16.1.2.2 – 16.1.3
f5big-ip_advanced_firewall_manager
f5big-ip_advanced_firewall_manager
f5big-ip_advanced_firewall_manager14.1.4.6 – 14.1.5
f5big-ip_advanced_firewall_manager15.1.5.1 – 15.1.8
f5big-ip_advanced_firewall_manager16.1.2.2 – 16.1.3
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics
f5big-ip_analytics
f5big-ip_analytics14.1.4.6 – 14.1.5
f5big-ip_analytics15.1.5.1 – 15.1.8
f5big-ip_analytics16.1.2.2 – 16.1.3
f5big-ip_apm
f5big-ip_application_acceleration_manager

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability targets the iControl SOAP CGI process; monitor for crashes or unexpected restarts of the iControl SOAP CGI daemon as a sign of exploitation attempts.
  • In appliance mode BIG-IP deployments, a successful exploit crosses a security boundary — treat any unexpected privilege escalation or cross-boundary activity on appliance-mode BIG-IP as a high-priority indicator.
  • Scope detection to authenticated sessions interacting with iControl SOAP; look for anomalous or malformed SOAP requests containing format string specifiers (e.g., %s, %n, %x) in request parameters sent to the iControl SOAP endpoint.
  • ·Only the following specific BIG-IP software versions are confirmed affected; ensure version checks are scoped precisely to these ranges and not applied broadly.
  • ·Software versions that have reached End of Technical Support (EoTS) are explicitly out of scope for this CVE evaluation — do not assume EoTS versions are safe or patched.
  • ·The security boundary crossing risk is specific to appliance mode BIG-IP deployments; standard (non-appliance) mode carries a different risk profile.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.