Security features bypass in BIG-IP - CVE-2022-33962

 

Security features bypass in BIG-IP - CVE-2022-33962

Published: August 4, 2022


Vulnerability identifier: #VU66088
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-33962
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass implemented security restrictions.

The vulnerability exists due to certain iRules commands may allow a user to bypass the access control restrictions for a self IP address, regardless of the port lockdown settings. A local user can use this vulnerability to connect to internal IP addresses or services through an iRule that allows unconstrained manipulation of the target of the pool or node commands.


Affected software

BIG-IP

How to mitigate CVE-2022-33962

Install updates from vendor's website.

BIG-IP - addressed in versions 14.1.5.1, 15.1.6.1, 16.1.3.1, 17.0.0.1

External References

Related Security Bulletins