Arbitrary Command Execution Vulnerability in F5 BIG-IP AFM
CVE-2022-28695

7.2HIGH

Key Information:

Vendor
F5
Vendor
CVE Published:
5 May 2022

Summary

An authenticated attacker with elevated privileges on F5 BIG-IP AFM can exploit a file upload vulnerability within the Configuration utility. By uploading a specially crafted file, the attacker gains the ability to execute arbitrary commands on the affected system. This vulnerability primarily affects versions 16.1.x, 15.1.x, 14.1.x, and 13.1.x that have not reached End of Technical Support (EoTS). It's crucial for administrators to update to the patched versions to mitigate potential attacks.

Affected Version(s)

BIG-IP AFM 16.1.x < 16.1.2.2

BIG-IP AFM 15.1.x < 15.1.5.1

BIG-IP AFM 14.1.x < 14.1.4.6

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.