CVE-2022-33947
Last modified
CVE-2022-33947 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, a vulnerability exists in undisclosed pages of the BIG-IP DNS Traffic Management User Interface (TMUI) that allows an authenticated attacker with at least operator role privileges to cause the Tomcat process to restart and perform unauthorized DNS requests and operations through undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, a vulnerability exists in undisclosed pages of the BIG-IP DNS Traffic Management User Interface (TMUI) that allows an authenticated attacker with at least operator role privileges to cause the Tomcat process to restart and perform unauthorized DNS requests and operations through undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Ip Domain Name System | >= 13.1.0, <= 13.1.5 |
| F5 | Big-Ip Domain Name System | >= 14.1.0, < 14.1.5 |
| F5 | Big-Ip Domain Name System | >= 15.1.0, < 15.1.6.1 |
| F5 | Big-Ip Domain Name System | >= 16.1.0, < 16.1.3 |
References
- https://support.f5.com/csp/article/K38893457Vendor Advisory
- https://support.f5.com/csp/article/K38893457Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-33947?
How severe is CVE-2022-33947?
How do I fix CVE-2022-33947?
Are you affected by CVE-2022-33947?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
