Cyber Resilience

CVE-2022-35243

High

Published: 04 August 2022

Published
04 August 2022
Modified
21 November 2024
KEV Added
Patch
CVSS Score v3.1 8.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
EPSS Score 0.0044 63.6th percentile
Risk Priority 18 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2022-35243 is a high-severity Improper Privilege Management (CWE-269) vulnerability in F5 Big-Ip Access Policy Manager. Its CVSS base score is 8.7 (High).

Operationally, ranked in the top 36.4% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability details

In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.5.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, using an undisclosed…

more

iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

f5
big-ip access policy manager
13.1.0 — 13.1.5 · 14.1.0 — 14.1.5 · 15.1.0 — 15.1.6.1
f5
big-ip advanced firewall manager
13.1.0 — 13.1.5 · 14.1.0 — 14.1.5 · 15.1.0 — 15.1.6.1
f5
big-ip analytics
13.1.0 — 13.1.5 · 14.1.0 — 14.1.5 · 15.1.0 — 15.1.6.1
f5
big-ip application acceleration manager
13.1.0 — 13.1.5 · 14.1.0 — 14.1.5 · 15.1.0 — 15.1.6.1
f5
big-ip application security manager
13.1.0 — 13.1.5 · 14.1.0 — 14.1.5 · 15.1.0 — 15.1.6.1
f5
big-ip domain name system
13.1.0 — 13.1.5 · 14.1.0 — 14.1.5 · 15.1.0 — 15.1.6.1
f5
big-ip fraud protection service
13.1.0 — 13.1.5 · 14.1.0 — 14.1.5 · 15.1.0 — 15.1.6.1
f5
big-ip global traffic manager
13.1.0 — 13.1.5 · 14.1.0 — 14.1.5 · 15.1.0 — 15.1.6.1
f5
big-ip link controller
13.1.0 — 13.1.5 · 14.1.0 — 14.1.5 · 15.1.0 — 15.1.6.1
f5
big-ip local traffic manager
13.1.0 — 13.1.5 · 14.1.0 — 14.1.5 · 15.1.0 — 15.1.6.1
+1 more product configuration(s) — see NVD for full list

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-269

Policy addresses roles, responsibilities, and privilege management to prevent improper privilege assignments.

addresses: CWE-269

Access supervision ensures privileges are assigned and managed without improper escalation or retention.

addresses: CWE-269

Assigning group/role memberships and access authorizations (privileges) while reviewing accounts addresses improper privilege management.

addresses: CWE-269

Enforces proper privilege management by requiring all decisions through the verified reference monitor.

addresses: CWE-269

By mandating division of duties across roles, the control enforces proper privilege management and prevents a single entity from controlling an entire sensitive process.

addresses: CWE-269

Implements core proper privilege management by restricting to only required rights.

addresses: CWE-269

Policy requires training on privilege management and least privilege, making it harder to exploit improper privilege management weaknesses.

addresses: CWE-269

Training covers proper privilege management practices, making incorrect privilege assignments less likely.

References