#VU66088 Security features bypass in BIG-IP - CVE-2022-33962

 

#VU66088 Security features bypass in BIG-IP - CVE-2022-33962

Published: August 4, 2022


Vulnerability identifier: #VU66088
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-33962
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
BIG-IP
Software vendor:
F5 Networks

Description

The vulnerability allows a local user to bypass implemented security restrictions.

The vulnerability exists due to certain iRules commands may allow a user to bypass the access control restrictions for a self IP address, regardless of the port lockdown settings. A local user can use this vulnerability to connect to internal IP addresses or services through an iRule that allows unconstrained manipulation of the target of the pool or node commands.


Remediation

Install updates from vendor's website.

External links