QID 376779
Date Published: 2022-08-10
QID 376779: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) Big-ip Monitor Configuration Vulnerability cve-2022-35735 (K13213418)
An authenticated attacker with Resource Administrator or Manager privileges can create or modify existing monitor objects in the Configuration utility in an undisclosed manner, leading to a privilege escalation.CVE-2022-35735
Vulnerable Component: BIG-IP ASM,LTM,APM
Affected Versions:
16.1.0 - 16.1.3
15.1.0 - 15.1.6
14.1.0 - 14.1.5
13.1.0 - 13.1.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
This vulnerability may allow an authenticated Resource Administrator or Manager attacker with access to the Configuration utility to create a configuration that elevates their privileges to Administrator. There is no data plane exposure; this is a control plane issue only.
- K13213418 -
support.f5.com/csp/article/K13213418
CVEs related to QID 376779
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K13213418 |
|