CVE-2022-28714
HIGHF5 BIG-IP APM <16.1.2.2, <15.1.5.1, <14.1.4.6, <13.1.5, <=12.1.x, <...
Title source: llmDescription
On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as well as F5 BIG-IP APM Clients 7.x versions prior to 7.2.1.5, a DLL Hijacking vulnerability exists in the BIG-IP Edge Client Windows Installer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Scores
CVSS v3
7.3
EPSS
0.0036
EPSS Percentile
58.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-427
Status
published
Affected Products (39)
f5/big-ip_access_policy_manager
f5/big-ip_access_policy_manager
f5/big-ip_access_policy_manager
f5/big-ip_access_policy_manager
f5/big-ip_access_policy_manager
f5/big-ip_access_policy_manager
f5/big-ip_access_policy_manager
f5/big-ip_access_policy_manager
f5/big-ip_access_policy_manager
f5/big-ip_access_policy_manager
f5/big-ip_access_policy_manager
f5/big-ip_access_policy_manager
f5/big-ip_access_policy_manager
f5/big-ip_access_policy_manager
f5/big-ip_access_policy_manager
... and 24 more
Timeline
Published
May 05, 2022
Tracked Since
Feb 18, 2026