CVE-2023-22283
Last modified
CVE-2023-22283 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. On versions beginning in 7.1.5 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client for Windows. User interaction and administrative privileges are required to exploit this vulnerability because the victim user needs to run the executable on the system and the attacker requires administrative privileges for modifying the files in the trusted search path. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
On versions beginning in 7.1.5 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client for Windows. User interaction and administrative privileges are required to exploit this vulnerability because the victim user needs to run the executable on the system and the attacker requires administrative privileges for modifying the files in the trusted search path. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Ip Access Policy Manager | >= 7.2.2, < 7.2.3.1 |
| F5 | Big-Ip Access Policy Manager | >= 13.1.0, <= 13.1.5 |
| F5 | Big-Ip Access Policy Manager | >= 14.1.0, <= 14.1.5 |
| F5 | Big-Ip Access Policy Manager | >= 15.1.0, <= 15.1.8 |
| F5 | Big-Ip Access Policy Manager | >= 16.1.0, <= 16.1.3 |
| F5 | Big-Ip Access Policy Manager | >= 17.0.0, < 17.0.0.2 |
| F5 | Big-Ip Edge | All versions |
References
- https://my.f5.com/manage/s/article/K07143733Vendor Advisory
- https://my.f5.com/manage/s/article/K07143733Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-22283?
How severe is CVE-2023-22283?
How do I fix CVE-2023-22283?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-22278m-FILTER prior to Ver.5.70R01 (Ver.5 Series) and m-FILTER pr…5.3
- CVE-2023-22279MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00…9.8
- CVE-2023-2228Cross-Site Request Forgery (CSRF) in GitHub repository modob…6.8
- CVE-2023-22280MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00…7.2
- CVE-2023-22281On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, …7.5
- CVE-2023-22282WAB-MAT Ver.5.0.0.8 and earlier starts another program with …7.3
- CVE-2023-22284Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2023-22285Improper access control for some Intel Unison software may a…7.5
- CVE-2023-22286Cross-site request forgery (CSRF) vulnerability in MAHO-PBX …8.1
- CVE-2023-22287Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2023-22288HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p…5.4
- CVE-2023-2229The Quick Post Duplicator for WordPress is vulnerable to SQL…8.8
Are you affected by CVE-2023-22283?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
