Context over chaos. Disconnected technologies, siloed data, and reactive processes can only get you so far. Protecting businesses in today’s threat landscape demands more than a set of security tools – it requires context.
That's where Avertium comes in
Security. It’s in our DNA. It’s elemental, foundational. Something that an always-on, everything’s-IoT-connected world depends on.
Helping mid-to-enterprise organizations protect assets and manage risk is our only business. Our mission is to make our customers’ world a safer place so that they may thrive in an always-on, connected world.
Best-in-class technology from our partners... backed by service excellence from Avertium.
Interested in becoming a partner?
With Avertium's deal registration, partners can efficiently and confidently connect with Avertium on opportunities to protect your deals.
Microsoft Copilot for Security analyzes and synthesizes high volumes of security data which can help healthcare cybersecurity teams do more with less.
Dive into our resource hub and explore top
cybersecurity topics along with what we do
and what we can do for you.
overview
This week, Rapid7 researchers discovered two high-severity vulnerabilities in F5 BIG-IP and BIG-IQ products running customized distribution of CentOS. CVE-2022-41622 is an unauthenticated remote code execution vulnerability impacting BIG-IP products, while CVE-2022-41800 is an authenticated remote code execution vulnerability impacting BIG-IQ products.
According to F5, an attacker may exploit CVE-2022-41622 to trick users who have Resource Administrator role privileges and are authenticated through basic authentication in iControl SOAP. Even though the vulnerability can only be exploited through the control plane, an attacker can compromise the complete system if successful.
Rapid7’s researchers stated that although CVE-2022-41622 is the more serious vulnerability, an attacker would only be successful if an administrator with an active session is tricked into visiting a malicious website with the same browser used for managing BIG-IP. The vulnerable versions of BIG-IP are as follows:
As for CVE-2022-41800, F5 stated that an authenticated attacker with valid user credentials assigned as Administrator may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. If successful, the vulnerability could allow the attacker to cross a security boundary. The vulnerable versions of BIG-IQ are as follows:
Although F5 is not aware of any exploitation incidents, they still recommend that all impacted customers request the engineering hotfix for their product version from F5 and install the hotfix manually.
F5 Recommends the following to mitigate CVE-2022-41622:
BIG-IP mitigation
F5 recommends the following to mitigate CVE-2022-41800 until you can install the fixed version:
BIG-IQ mitigation
At this time, there are no known IoCs associated with CVE-2022-41622 and CVE-2022-41800. Avertium’s threat hunters remain vigilant in locating IoCs for our customers. Should any be located, Avertium will disclose them as soon as possible. For more information on how Avertium can help protect your organization, please reach out to your Avertium Service Delivery Manager or Account Executive.
F5 fixed 2 high-severity RCE bugs in its productsSecurity Affairs
Appliance mode iControl REST vulnerability CVE-2022-41800 (f5.com)
iControl SOAP vulnerability CVE-2022-41622 (f5.com)
F5 fixes two remote code execution flaws in BIG-IP, BIG-IQ (bleepingcomputer.com)