QID 377814
Date Published: 2022-12-19
QID 377814: F5 BIG-IP AFM TMUI Vulnerability CVE-2022-28695 (K08510472)
An authenticated attacker with high privileges can upload a maliciously crafted file to the BIG-IP AFM Configuration utility, which allows an attacker to run arbitrary commands.
Vulnerable Component:
BIG-IP AFM,CGNAT,PEM
Affected Versions:
16.1.0 - 16.1.2
15.1.0 - 15.1.5
14.1.0 - 14.1.4
13.1.0. - 13.1.4
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
This vulnerability may allow an authenticated high-privilege attacker who has network access to the Configuration utility through the BIG-IP management port or self IP addresses to run arbitrary system commands, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.
- K08510472 -
support.f5.com/csp/article/K08510472
CVEs related to QID 377814
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K08510472 |
|