PT-2022-17831 · F5 · F5 Big-Ip

Published

2022-05-05

·

Updated

2023-01-24

·

CVE-2022-26415

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions F5 BIG-IP versions 12.1.x F5 BIG-IP versions 13.1.x prior to 13.1.5 F5 BIG-IP versions 14.1.x prior to 14.1.4.6 F5 BIG-IP versions 15.1.x prior to 15.1.5.1 F5 BIG-IP versions 16.1.x prior to 16.1.2.2
Description An authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint.
Recommendations For F5 BIG-IP version 12.1.x, update to a version that is still supported and apply the necessary patches. For F5 BIG-IP versions 13.1.x, update to version 13.1.5 or later. For F5 BIG-IP versions 14.1.x, update to version 14.1.4.6 or later. For F5 BIG-IP versions 15.1.x, update to version 15.1.5.1 or later. For F5 BIG-IP versions 16.1.x, update to version 16.1.2.2 or later.

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-26415

Affected Products

F5 Big-Ip