In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.5.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, using an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published: 2022-08-04T17:49:19.345871Z

Updated: 2024-09-16T22:15:58.079Z

Reserved: 2022-07-19T00:00:00

Link: CVE-2022-35243

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-08-04T18:15:10.680

Modified: 2022-08-10T19:11:54.747

Link: CVE-2022-35243

cve-icon Redhat

No data.