Skip to main content

F5 Releases Security Updates for BIG-IP Product Lines

Updates address 2 vulnerabilities rated as High impact and an article on BIG-IP and BIG-IQ improvements

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Updates address 2 vulnerabilities rated as High impact and an article on BIG-IP and BIG-IQ improvements


Affected platforms

The following platforms are known to be affected:

The following platforms are also known to be affected:

  • NGINX
  • Other Products
  • Services

Threat details

Introduction

F5 has released an overview of vulnerabilities for some of their networking products, including BIG-IP and BIG-IQ Centralized Management. A BIG-IP and BIG-IQ improvements article as well as two vulnerabilities are addressed in the advisory, with both vulnerabilities rated as High impact.

The first vulnerability, known as CVE-2022-41622, may allow a cross-site request forgery (CSRF) attack that could allow an attacker to compromise the complete system. The second vulnerability, known as CVE-2022-41800, could allow an authenticated attacker with valid user credentials assigned the Administrator role to bypass Appliance mode restrictions, thereby allowing the attacker to cross a security boundary. 

Proof-of-concept has been publicly released for CVE-2022-41622

There has been proof-of-concept code released on GitHub for CVE-2022-41622.


Threat updates

Date Update
18 Nov 2022 Updated Cyber alert to reflect release of proof-of-concept code.

Remediation advice

Affected organisations are encouraged to review K97843387: Overview of F5 vulnerabilities (November 2022) and apply any relevant updates or mitigations.



Last edited: 18 November 2022 12:04 pm