CVE-2022-25946: High severity f5 access policy manager vulnerability
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, when running in Appliance mode, an authenticated attacker with Administrator role privilege may be able to bypass Appliance mode restrictions due to a missing integrity check in F5 BIG-IP Guided Configuration. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-25946?
CVE-2022-25946 is considered a high severity vulnerability due to the potential for an authenticated attacker to bypass appliance security controls.
How do I fix CVE-2022-25946?
To fix CVE-2022-25946, users should upgrade to the latest versions of F5 BIG-IP products that are vulnerable, as detailed in official F5 documentation.
What products are affected by CVE-2022-25946?
CVE-2022-25946 affects various versions of F5 BIG-IP Advanced WAF, ASM, and Guided Configuration prior to version 9.0.
What kind of attacker can exploit CVE-2022-25946?
An authenticated attacker with Administrator role privilege can potentially exploit CVE-2022-25946.
What actions should organizations take regarding CVE-2022-25946?
Organizations should conduct an inventory of their affected F5 BIG-IP systems and apply necessary updates to mitigate CVE-2022-25946.