SB2022080410 - Security restrictions bypass in BIG-IP iRules
Published: August 4, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security features bypass (CVE-ID: CVE-2022-33962)
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to certain iRules commands may allow a user to bypass the access control restrictions for a self IP address, regardless of the port lockdown settings. A local user can use this vulnerability to connect to internal IP addresses or services through an iRule that allows unconstrained manipulation of the target of the pool or node commands.
Remediation
Install update from vendor's website.