CVE-2022-27806 Information
Jun 07, 2022
cve
Description
On all versions of 16.1.x 15.1.x 14.1.x 13.1.x 12.1.x and 11.6.x of F5 BIG-IP Advanced WAF ASM and ASM and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0 when running in Appliance mode an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing command injection vulnerabilities in undisclosed URIs in F5 BIG-IP Guided Configuration. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Reference
https://support.f5.com/csp/article/K68647001
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.2
Share on: