CVE-2022-35728: iControl REST vulnerability CVE-2022-35728
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ version 8.x before 8.2.0 and all versions of 7.x, an authenticated user's iControl REST token may remain valid for a limited time after logging out from the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-35728?
CVE-2022-35728 has been classified as a high severity vulnerability.
How do I fix CVE-2022-35728?
To fix CVE-2022-35728, it's recommended to upgrade to the latest patched version of the affected F5 BIG-IP or BIG-IQ software.
Which versions are affected by CVE-2022-35728?
CVE-2022-35728 affects F5 BIG-IP versions prior to 17.0.0.1, 16.1.3.1, 15.1.6.1, 14.1.5.1, and all versions of 13.1.x, as well as all versions of BIG-IQ before 8.2.0 and all version of 7.x.
What type of attacks can exploit CVE-2022-35728?
CVE-2022-35728 can potentially be exploited to maintain unauthorized access via a valid iControl REST token of an authenticated user.
Is there a workaround for CVE-2022-35728?
Currently, there are no suggested workarounds for CVE-2022-35728 beyond upgrading to the patched software.