CVE-2022-35735: BIG-IP monitor configuration vulnerability CVE-2022-35735
In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, an authenticated attacker with Resource Administrator or Manager privileges can create or modify existing monitor objects in the Configuration utility in an undisclosed manner leading to a privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-35735.
What products are affected by this vulnerability?
F5 BIG-IP Access Policy Manager, F5 BIG-IP Advanced Firewall Manager, F5 BIG-IP Analytics, F5 BIG-IP Application Acceleration Manager, F5 BIG-IP Application Security Manager, F5 BIG-IP Domain Name System, F5 BIG-IP Fraud Protection Service, F5 BIG-IP Global Traffic Manager, F5 BIG-IP Link Controller, F5 BIG-IP Local Traffic Manager, F5 BIG-IP Policy Enforcement Manager.
What is the severity of CVE-2022-35735?
The severity of CVE-2022-35735 is high with a CVSS score of 7.2.
How can an attacker exploit this vulnerability?
An authenticated attacker with Resource Administrator or Manager privileges can create or modify existing monitor objects in the Configuration utility.
Is there a fix available for this vulnerability?
Yes, upgrading to the patched versions listed in the vendor advisory will fix this vulnerability.