CVE-2022-41617

In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, When the Advanced WAF / ASM module is provisioned, an authenticated remote code execution vulnerability exists in the BIG-IP iControl REST interface.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
f5CNA
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
f5big-ip_advanced_web_application_firewall
13.1.0 ≤
𝑥
< 13.1.5.1
f5big-ip_advanced_web_application_firewall
14.1.0 ≤
𝑥
< 14.1.5.1
f5big-ip_advanced_web_application_firewall
15.1.0 ≤
𝑥
< 15.1.6.1
f5big-ip_advanced_web_application_firewall
16.1.0 ≤
𝑥
< 16.1.3.1
f5big-ip_application_security_manager
13.1.0 ≤
𝑥
< 13.1.5.1
f5big-ip_application_security_manager
14.1.0 ≤
𝑥
< 14.1.5.1
f5big-ip_application_security_manager
15.1.0 ≤
𝑥
< 15.1.6.1
f5big-ip_application_security_manager
16.1.0 ≤
𝑥
< 16.1.3.1
𝑥
= Vulnerable software versions