CVE-2022-41800

high

Description

In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

References

https://support.f5.com/csp/article/K13325942

Details

Source: MITRE

Published: 2022-12-07

Updated: 2022-12-12

Type: CWE-77