QID 376593
Date Published: 2022-05-16
QID 376593: F5 BIG-IP Application Security Manager (ASM), Access Policy Manager (APM) Restriction Bypass Vulnerability (K68647001)
When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing command injection vulnerabilities in undisclosed URIs in F5 BIG-IP Guided Configuration. (CVE-2022-27806)
Affected Versions:
16.1.0 - 16.1.2
15.1.0 - 15.1.5
14.1.0 - 14.1.4
13.1.0.8 - 13.1.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
In Appliance mode, an authenticated attacker with valid credentials assigned the Administrator role may be able to bypass Appliance mode restrictions. This is a control plane issue; there is no data plane exposure. Appliance mode is enforced by a specific license or may be enabled or disabled for individual Virtual Clustered Multiprocessing (vCMP) guest instances.
- K68647001 -
support.f5.com/csp/article/K68647001
CVEs related to QID 376593
| Advisory ID | Software | Component | Link |
|---|