CVE-2022-41800
HIGH 8.7EPSS 76.9%
In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVSS v3.1
- 8.7 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N - CVSS v3.1
- 8.7 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N - EPSS
- 76.87% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- high · CWE-77
- Published
- 2022-12-07
- Updated
- 2025-04-23
Proof-of-concept exploits (1)
- j-baines/tippa-my-tongue1★ · 2023-04-12