CVE-2022-28695 PUBLISHED CVSS 7.199999809265137 HIGH

On F5 BIG-IP AFM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, an authenticated attacker with high privileges can upload a maliciously crafted file to the BIG-IP AFM Configuration utility, which allows an attacker to run arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

EPSS 0.44% · 63.0th percentile

Risk Scores

CVSS v3.1
7.199999809265137
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.44%
63.0th percentile

Affected Products

VendorProductVersions
f5big-ip_advanced_firewall_manager16.1.1, 15.1.5, 16.1.0
F5BIG-IP AFM11.6.x, 17.0.0, 16.1.x

Timeline

References

…and 25 more

Open in Interactive Console →