CVE-2022-41800
In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- Affected products
- Big-Ip
- f5 Big-ip Access Policy Manager
- ≤ 13.1.5, 14.1.5, 15.1.8, 16.1.3, 17.0.0
- f5 Big-ip Advanced Firewall Manager
- ≤ 17.0.0
- f5 Big-ip Analytics
- ≤ 13.1.5, 14.1.5, 15.1.8, 16.1.3, 17.0.0
- f5 Big-ip Application Acceleration Manager
- ≤ 13.1.5, 14.1.5, 15.1.8, 16.1.3, 17.0.0
- f5 Big-ip Application Security Manager
- ≤ 13.1.5, 14.1.5, 15.1.8, 16.1.3, 17.0.0
- f5 Big-ip Domain Name System
- ≤ 13.1.5, 14.1.5, 15.1.8, 16.1.3, 17.0.0
- CVSS 3.1
- 8.7 HIGH
- EPSS
- 65.7% (99th percentile)
- Weakness
- CWE-77
- NVD status
- Modified
- Published
- 2022-12-07
CVE-2022-41800 at NVD
6 known exploits for CVE-2022-41800
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Missing Authentication for Critical Function in F5 Big-Ip_Access_Policy_Manager
F5 Big-IP Create Administrative User Exploit
F5 Big-IP Create Administrative User
F5 BIG-IP iControl Remote Command Execution
F5 BIG-IP iControl Cross Site Request Forgery Exploit
F5 BIG-IP iControl Cross Site Request Forgery