CVE-2022-41622
HIGHF5 BIG-IP and BIG-IQ - Cross-Site Request Forgery via iControl SOAP
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2022-41622.
PoCs published by rbowes-r7, Ron Bowes, including Metasploit module exploits/linux/http/f5_icontrol_soap_csrf_rce_cve_2022_41622.
AI-analyzed exploit summary This is a functional proof-of-concept exploit for CVE-2022-41622, a CSRF vulnerability in F5 Big-IP's SOAP interface leading to remote code execution. It demonstrates adding a root user and achieving remote shell access via a symlink bypass.
Description
In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Exploits (2)
This is a functional proof-of-concept exploit for CVE-2022-41622, a CSRF vulnerability in F5 Big-IP's SOAP interface leading to remote code execution. It demonstrates adding a root user and achieving remote shell access via a symlink bypass.
This Metasploit module exploits CVE-2022-41622, a CSRF vulnerability in F5 BIG-IP's iControl SOAP API, to write arbitrary files as root. It leverages an authenticated admin's session to overwrite specific files, achieving RCE either post-reboot or on next interactive login.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H