F5 Releases Security Updates for BIG-IP Product Lines
Updates address 2 vulnerabilities rated as High impact and an article on BIG-IP and BIG-IQ improvements
Summary
Updates address 2 vulnerabilities rated as High impact and an article on BIG-IP and BIG-IQ improvements
Affected platforms
The following platforms are known to be affected:
The following platforms are also known to be affected:
- NGINX
- Other Products
- Services
Threat details
Introduction
F5 has released an overview of vulnerabilities for some of their networking products, including BIG-IP and BIG-IQ Centralized Management. A BIG-IP and BIG-IQ improvements article as well as two vulnerabilities are addressed in the advisory, with both vulnerabilities rated as High impact.
The first vulnerability, known as CVE-2022-41622, may allow a cross-site request forgery (CSRF) attack that could allow an attacker to compromise the complete system. The second vulnerability, known as CVE-2022-41800, could allow an authenticated attacker with valid user credentials assigned the Administrator role to bypass Appliance mode restrictions, thereby allowing the attacker to cross a security boundary.
Proof-of-concept has been publicly released for CVE-2022-41622
There has been proof-of-concept code released on GitHub for CVE-2022-41622.
Threat updates
| Date | Update |
|---|---|
| 18 Nov 2022 | Updated Cyber alert to reflect release of proof-of-concept code. |
Remediation advice
Affected organisations are encouraged to review K97843387: Overview of F5 vulnerabilities (November 2022) and apply any relevant updates or mitigations.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 18 November 2022 12:04 pm