← volver
CVE-2022-33947

BIG-IP DNS TMUI Vulnerability CVE-2022-33947

CVSS 5.4 MEDIUMEPSS 0.6%CWE-502
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.4EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
04 ago 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, a vulnerability exists in undisclosed pages of the BIG-IP DNS Traffic Management User Interface (TMUI) that allows an authenticated attacker with at least operator role privileges to cause the Tomcat process to restart and perform unauthorized DNS requests and operations through undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Productos afectados
F5 · BIG-IP DNS

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →