Arbitrary Command Execution Vulnerability in F5 BIG-IP AFM
CVE-2022-28695
7.2HIGH
What is CVE-2022-28695?
An authenticated attacker with elevated privileges on F5 BIG-IP AFM can exploit a file upload vulnerability within the Configuration utility. By uploading a specially crafted file, the attacker gains the ability to execute arbitrary commands on the affected system. This vulnerability primarily affects versions 16.1.x, 15.1.x, 14.1.x, and 13.1.x that have not reached End of Technical Support (EoTS). It's crucial for administrators to update to the patched versions to mitigate potential attacks.
Affected Version(s)
BIG-IP AFM 16.1.x < 16.1.2.2
BIG-IP AFM 15.1.x < 15.1.5.1
BIG-IP AFM 14.1.x < 14.1.4.6