#VU66088 Security features bypass in BIG-IP - CVE-2022-33962
Published: August 4, 2022
BIG-IP
F5 Networks
Description
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to certain iRules commands may allow a user to bypass the access control restrictions for a self IP address, regardless of the port lockdown settings. A local user can use this vulnerability to connect to internal IP addresses or services through an iRule that allows unconstrained manipulation of the target of the pool or node commands.