Vulnerability record · CVE-2022-41800 · published 7 December 2022
CVE-2022-41800: BIG-IP Appliance mode bypass via iControl REST command injection
F5 · Big Ip Access Policy Manager
In all versions of BIG-IP running in Appliance mode, an authenticated user with the Administrator role can bypass Appliance mode restrictions through an undisclosed iControl REST endpoint. The flaw is classified as command injection (CWE-77) and lets the attacker cross a security boundary that Appliance mode is meant to enforce.
Description
In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Automated analysis
high priorityCVSS 8.7 with scope change and high confidentiality/integrity impact, plus very high EPSS, though exploitation requires an already-authenticated Administrator account.
What it is
In all versions of BIG-IP running in Appliance mode, an authenticated user with the Administrator role can bypass Appliance mode restrictions through an undisclosed iControl REST endpoint. The flaw is classified as command injection (CWE-77) and lets the attacker cross a security boundary that Appliance mode is meant to enforce.
Impact
An attacker with Administrator rights gains the ability to escape Appliance mode restrictions and cross a security boundary, with high impact to confidentiality and integrity of the affected system. Availability is not impacted per the CVSS vector.
Attack surface
Reachable over the network through an iControl REST endpoint; the attacker must already be authenticated and hold the Administrator role, and no user interaction is required. The specific endpoint is not disclosed in the record.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware usage is documented in the record, but EPSS is very high (0.76866, 99.5th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Upgrade BIG-IP to a fixed release per F5 advisory K13325942; note that EoTS versions are not evaluated and should be replaced.
- Restrict Administrator-role accounts to the minimum necessary personnel and review role assignments for Appliance mode deployments.
- Limit network access to iControl REST interfaces to trusted management networks only.
- Monitor and alert on Administrator-role activity that modifies Appliance mode settings or uses unusual REST endpoints.
Detection
- Audit iControl REST API logs for Administrator-role calls to undocumented or unexpected endpoints.
- Alert on changes to Appliance mode configuration or attempts to disable it.
- Correlate Administrator account activity with configuration changes outside normal change windows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.f5.com/csp/article/K13325942 | Vendor Advisory |
| https://support.f5.com/csp/article/K13325942 | Vendor Advisory |
Track CVE-2022-41800 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-41800), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.