CVE-2022-41617: BIG-IP Advanced WAF and ASM iControl REST vulnerability CVE-2022-41617
In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, When the Advanced WAF / ASM module is provisioned, an authenticated remote code execution vulnerability exists in the BIG-IP iControl REST interface.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
F5 BIG-IP Advanced WAF and ASM (iControl REST)to a version that resolves this vulnerability.Fixed in 16.1.3.1 - Upgrade
Upgrade
F5 BIG-IP Advanced WAF and ASM (iControl REST)to a version that resolves this vulnerability.Fixed in 15.1.6.1 - Upgrade
Upgrade
F5 BIG-IP Advanced WAF and ASM (iControl REST)to a version that resolves this vulnerability.Fixed in 14.1.5.1 - Upgrade
Upgrade
F5 BIG-IP Advanced WAF and ASM (iControl REST)to a version that resolves this vulnerability.Fixed in 13.1.5.1
Event History
Frequently Asked Questions
What is CVE-2022-41617?
CVE-2022-41617 is a remote code execution vulnerability in the BIG-IP iControl REST interface.
Which software versions are affected by CVE-2022-41617?
Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1 of F5 Big-ip Advanced Web Application Firewall and F5 BIG-IP Application Security Manager are affected by CVE-2022-41617.
What is the severity of CVE-2022-41617?
CVE-2022-41617 has a severity value of 7.2, which is considered high.
How can I fix CVE-2022-41617?
To fix CVE-2022-41617, update your F5 Big-ip Advanced Web Application Firewall or F5 BIG-IP Application Security Manager to version 16.1.3.1, 15.1.6.1, 14.1.5.1, or 13.1.5.1.
Where can I find more information about CVE-2022-41617?
More information about CVE-2022-41617 can be found at the following link: [link](https://support.f5.com/csp/article/K11830089)