CVE-2022-27806 vulnerability in F5 Networks Products
Published on May 5, 2022
On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, when running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing command injection vulnerabilities in undisclosed URIs in F5 BIG-IP Guided Configuration. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Vulnerability Analysis
CVE-2022-27806 is exploitable with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is a Command Injection Vulnerability?
The software constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVE-2022-27806 has been classified to as a Command Injection vulnerability or weakness.
Products Associated with CVE-2022-27806
Want to know whenever a new CVE is published for F5 Networks products? stack.watch will email you.
Affected Versions
F5 BIG-IP (Advanced WAF, APM, ASM):- Version 16.1.x is affected.
- Version 15.1.x is affected.
- Version 14.1.x is affected.
- Version 13.1.x is affected.
- Version 12.1.x is affected.
- Version 11.6.x is affected.
- Version 17.0.0 and below 17.0.x* is unaffected.
- Version All and below 9.0 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.