CVE-2022-28695: Input Validation
On F5 BIG-IP AFM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, an authenticated attacker with high privileges can upload a maliciously crafted file to the BIG-IP AFM Configuration utility, which allows an attacker to run arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28695?
CVE-2022-28695 is considered to have a high severity rating due to the potential for authenticated attackers to exploit the vulnerability.
How do I fix CVE-2022-28695?
To fix CVE-2022-28695, you should update your F5 BIG-IP AFM to the latest version that addresses this vulnerability.
Which versions of F5 BIG-IP AFM are affected by CVE-2022-28695?
CVE-2022-28695 affects F5 BIG-IP AFM versions 13.1.x prior to 13.1.5, 14.1.x prior to 14.1.4.6, 15.1.x prior to 15.1.5.1, and 16.1.x prior to 16.1.2.2.
Can CVE-2022-28695 be exploited remotely?
No, CVE-2022-28695 requires the attacker to have authenticated access with high privileges to exploit the vulnerability.
What kind of attack can CVE-2022-28695 lead to?
CVE-2022-28695 can allow an authenticated attacker to upload a maliciously crafted file, potentially compromising the integrity of the BIG-IP AFM system.