CVE-2022-41836
BIG-IP Advanced WAF and ASM bd vulnerability CVE-2022-41836
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
When an 'Attack Signature False Positive Mode' enabled security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.
Cuando es configurada una política de seguridad habilitada para el "Attack Signature False Positive Mode" en un servidor virtual, las peticiones no reveladas pueden causar la finalización del proceso bd
*Credits:
This issue was discovered internally by F5.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-09-30 CVE Reserved
- 2022-10-19 CVE Published
- 2024-05-11 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.f5.com/csp/article/K47204506 | 2022-10-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
F5 Search vendor "F5" | Big-ip Advanced Web Application Firewall Search vendor "F5" for product "Big-ip Advanced Web Application Firewall" | >= 15.1.0 < 15.1.7 Search vendor "F5" for product "Big-ip Advanced Web Application Firewall" and version " >= 15.1.0 < 15.1.7" | - |
Affected
| ||||||
F5 Search vendor "F5" | Big-ip Advanced Web Application Firewall Search vendor "F5" for product "Big-ip Advanced Web Application Firewall" | >= 16.1.0 < 16.1.3.1 Search vendor "F5" for product "Big-ip Advanced Web Application Firewall" and version " >= 16.1.0 < 16.1.3.1" | - |
Affected
| ||||||
F5 Search vendor "F5" | Big-ip Advanced Web Application Firewall Search vendor "F5" for product "Big-ip Advanced Web Application Firewall" | 17.0.0 Search vendor "F5" for product "Big-ip Advanced Web Application Firewall" and version "17.0.0" | - |
Affected
| ||||||
F5 Search vendor "F5" | Big-ip Application Security Manager Search vendor "F5" for product "Big-ip Application Security Manager" | >= 15.1.0 < 15.1.7 Search vendor "F5" for product "Big-ip Application Security Manager" and version " >= 15.1.0 < 15.1.7" | - |
Affected
| ||||||
F5 Search vendor "F5" | Big-ip Application Security Manager Search vendor "F5" for product "Big-ip Application Security Manager" | >= 16.1.0 < 16.1.3.1 Search vendor "F5" for product "Big-ip Application Security Manager" and version " >= 16.1.0 < 16.1.3.1" | - |
Affected
| ||||||
F5 Search vendor "F5" | Big-ip Application Security Manager Search vendor "F5" for product "Big-ip Application Security Manager" | 17.0.0 Search vendor "F5" for product "Big-ip Application Security Manager" and version "17.0.0" | - |
Affected
|