CVE-2022-27806 Information

Description

On all versions of 16.1.x 15.1.x 14.1.x 13.1.x 12.1.x and 11.6.x of F5 BIG-IP Advanced WAF ASM and ASM and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0 when running in Appliance mode an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing command injection vulnerabilities in undisclosed URIs in F5 BIG-IP Guided Configuration. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Reference

https://support.f5.com/csp/article/K68647001

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction Required

HIGH

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.2

Share on: