BIG-IP <17/16.1/15.1/14.1/13.1: iControl REST token persists after logout
CVE-2022-35728 Published on August 4, 2022
iControl REST vulnerability CVE-2022-35728
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ version 8.x before 8.2.0 and all versions of 7.x, an authenticated user's iControl REST token may remain valid for a limited time after logging out from the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Vulnerability Analysis
CVE-2022-35728 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Products Associated with CVE-2022-35728
Want to know whenever a new CVE is published for F5 Networks products? stack.watch will email you.
Affected Versions
F5 BIG-IP:- Version 13.1.0 and below 13.1.x* is affected.
- Version 14.1.x and below 14.1.5.1 is affected.
- Version 15.1.x and below 15.1.6.1 is affected.
- Version 16.1.x and below 16.1.3.1 is affected.
- Version 17.0.x and below 17.0.0.1 is affected.
- Version 8.0.x and below 8.2.0 is affected.
- Version 7.0.0 and below 7.x* is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.