Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-34851— BIG-IP and BIG-IQ iControl SOAP vulnerability CVE-2022-34851

CVSS 4.3 · Medium EPSS 0.42% · P62
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-34851

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
BIG-IP and BIG-IQ iControl SOAP vulnerability CVE-2022-34851
Source: NVD (National Vulnerability Database)
Vulnerability Description
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ Centralized Management all versions of 8.x, an authenticated attacker may cause iControl SOAP to become unavailable through undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
输入验证不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
F5 BIG-IP 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
F5 BIG-IP是美国F5公司的一款集成了网络流量管理、应用程序安全管理、负载均衡等功能的应用交付平台。 F5 BIG-IP存在输入验证错误漏洞,经过身份验证的攻击者可能会通过未公开的请求导致 iControl SOAP 变得不可用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
F5BIG-IP 13.1.0 ~ 13.1.x* -
F5BIG-IQ Centralized Management 7.0.0 ~ 7.x* -

II. Public POCs for CVE-2022-34851

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-34851

登录查看更多情报信息。

Same Patch Batch · F5 · 2022-08-04 · 21 CVEs total

CVE-2022-352438.7 HIGHAuthenticated iControl REST in Appliance mode vulnerability CVE-2022-35243
CVE-2022-357288.1 HIGHiControl REST vulnerability CVE-2022-35728
CVE-2022-352727.5 HIGHBIG-IP HTTP MRF vulnerability CVE-2022-35272
CVE-2022-352457.5 HIGHBIG-IP APM access policy vulnerability CVE-2022-35245
CVE-2022-352407.5 HIGHBIG-IP Message Routing MQTT vulnerability CVE-2022-35240
CVE-2022-352367.5 HIGHHTTP2 profile vulnerability CVE-2022-35236
CVE-2022-348627.5 HIGHTMM vulnerability CVE-2022-34862
CVE-2022-324557.5 HIGHTMM vulnerability CVE-2022-32455
CVE-2022-346557.5 HIGHTMM vulnerability CVE-2022-34655
CVE-2022-346517.5 HIGHBIG-IP TLS 1.3 iRule vulnerability CVE-2022-34651
CVE-2022-332037.5 HIGHBIG-IP APM and F5 SSL Orchestrator vulnerability CVE-2022-33203
CVE-2022-357357.2 HIGHBIG-IP monitor configuration vulnerability CVE-2022-35735
CVE-2022-314736.8 MEDIUMBIG-IP APM Appliance mode vulnerability CVE-2022-31473
CVE-2022-339626.7 MEDIUMBIG-IP iRule vulnerability CVE-2022-33962
CVE-2022-305356.5 MEDIUMNGINX Ingress Controller vulnerability CVE-2022-30535
CVE-2022-352416.5 MEDIUMNGINX Instance Manager vulnerability CVE-2022-35241
CVE-2022-348445.9 MEDIUMBIG-IP and BIG-IQ AWS vulnerability CVE-2022-34844
CVE-2022-339475.4 MEDIUMBIG-IP DNS TMUI Vulnerability CVE-2022-33947
CVE-2022-348654.8 MEDIUMTraffic intelligence feeds vulnerability CVE-2022-34865
CVE-2022-339683.7 LOWBIG-IP LTM and APM NTLM vulnerability CVE-2022-33968

IV. Related Vulnerabilities

V. Comments for CVE-2022-34851

No comments yet


Leave a comment