CVE-2022-33947
BIG-IP DNS TMUI Vulnerability CVE-2022-33947
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, a vulnerability exists in undisclosed pages of the BIG-IP DNS Traffic Management User Interface (TMUI) that allows an authenticated attacker with at least operator role privileges to cause the Tomcat process to restart and perform unauthorized DNS requests and operations through undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
En BIG-IP versiones 16.1.x anteriores a 16.1.3, 15.1.x anteriores a 15.1.6.1, 14.1.x anteriores a 14.1.5 y todas las versiones de 13.1.x, se presenta una vulnerabilidad en páginas no reveladas de la interfaz de usuario de administración del tráfico de DNS de BIG-IP (TMUI) que permite a un atacante autenticado con al menos privilegios de rol de operador llevar a cabo el reinicio del proceso Tomcat y realizar peticiones y operaciones DNS no autorizadas a través de peticiones no reveladas. Nota: Las versiones de software que han alcanzado el Fin del Soporte Técnico (EoTS) no son evaluadas
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-07-19 CVE Reserved
- 2022-08-04 CVE Published
- 2024-02-24 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.f5.com/csp/article/K38893457 | 2022-08-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
F5 Search vendor "F5" | Big-ip Domain Name System Search vendor "F5" for product "Big-ip Domain Name System" | >= 13.1.0 <= 13.1.5 Search vendor "F5" for product "Big-ip Domain Name System" and version " >= 13.1.0 <= 13.1.5" | - |
Affected
| ||||||
F5 Search vendor "F5" | Big-ip Domain Name System Search vendor "F5" for product "Big-ip Domain Name System" | >= 14.1.0 < 14.1.5 Search vendor "F5" for product "Big-ip Domain Name System" and version " >= 14.1.0 < 14.1.5" | - |
Affected
| ||||||
F5 Search vendor "F5" | Big-ip Domain Name System Search vendor "F5" for product "Big-ip Domain Name System" | >= 15.1.0 < 15.1.6.1 Search vendor "F5" for product "Big-ip Domain Name System" and version " >= 15.1.0 < 15.1.6.1" | - |
Affected
| ||||||
F5 Search vendor "F5" | Big-ip Domain Name System Search vendor "F5" for product "Big-ip Domain Name System" | >= 16.1.0 < 16.1.3 Search vendor "F5" for product "Big-ip Domain Name System" and version " >= 16.1.0 < 16.1.3" | - |
Affected
|