SB2022080410 - Security restrictions bypass in BIG-IP iRules



SB2022080410 - Security restrictions bypass in BIG-IP iRules

Published: August 4, 2022

Security Bulletin ID SB2022080410
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security features bypass (CVE-ID: CVE-2022-33962)

The vulnerability allows a local user to bypass implemented security restrictions.

The vulnerability exists due to certain iRules commands may allow a user to bypass the access control restrictions for a self IP address, regardless of the port lockdown settings. A local user can use this vulnerability to connect to internal IP addresses or services through an iRule that allows unconstrained manipulation of the target of the pool or node commands.


Remediation

Install update from vendor's website.