QID 377655
Date Published: 2022-11-14
QID 377655: F5 BIG-IP Application Security Manager (ASM) Big-ip Application Security Manager (ASM) icontrol rest Vulnerability cve-2022-41617 (K11830089)
When the F5 BIG-IP Advanced WAF or BIG-IP ASM module is provisioned, an authenticated remote code execution vulnerability exists in the BIG-IP iControl REST interface.CVE-2022-41617
Vulnerable Component: BIG-IP ASM
Affected Versions:
16.1.0 - 16.1.3
15.1.0 - 15.1.6
14.1.0 - 14.1.5
13.1.0 - 13.1.5
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
On systems deployed in Standard or Appliance mode, this vulnerability may allow a high privileged authenticated attacker with network access to the iControl REST interface to run arbitrary system commands, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only. Appliance mode is enforced by a specific license or may be enabled or disabled for individual Virtual Clustered Multiprocessing (vCMP) guest instances. For more information about Appliance mode, refer to K12815: Overview of Appliance mode.
- K11830089 -
support.f5.com/csp/article/K11830089
CVEs related to QID 377655
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K11830089 |
|