CVE-2024-22093

CWE-77Command Injection4 documents4 sources
Severity
8.7HIGH
EPSS
0.3%
top 44.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14

Description

When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:NExploitability: 2.3 | Impact: 5.8

Affected Packages13 packages

CVEListV5f5/big-ip17.1.017.1.1+2
NVDf5/big-ip_analytics15.1.015.1.9+2
NVDf5/big-ip_link_controller15.1.015.1.9+2
NVDf5/big-ip_domain_name_system15.1.015.1.9+2

🔴Vulnerability Details

2
CVEList
Appliance mode iControl REST vulnerability2024-02-14
GHSA
GHSA-4x3g-wfmq-27q5: When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-blade2024-02-14

📋Vendor Advisories

1
F5
CVE-2024-22093: When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iCon...2024-02-14
CVE-2024-22093 (HIGH CVSS 8.7) | When running in appliance mode | cvebase.io