← Back to browse · API

CVE-2022-41800

Severity
HIGH
CVSS
8.7
EPSS
0.62406
Risk score
56.64
CISA KEV
No
PoC
No
Published
2022-12-07
Modified
2025-04-23
First seen
2026-08-07
Aliases
EUVD-2022-44968, GHSA-CQCJ-7VQR-P254
Products
F5:BIG-IP 13.1.x, F5:BIG-IP 14.1.x, F5:BIG-IP 15.1.x, F5:BIG-IP 16.1.x, F5:BIG-IP 17.0.x
Sources
euvd EUVD-2022-44968

Description

In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

References