Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-22283


On versions beginning in 7.1.5 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client for Windows. User interaction and administrative privileges are required to exploit this vulnerability because the victim user needs to run the executable on the system and the attacker requires administrative privileges for modifying the files in the trusted search path. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.


Published

2023-02-01T18:15:10.727

Last Modified

2024-11-21T07:44:27.347

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-427
  • Type: Primary
    CWE-427

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application f5 big-ip_access_policy_manager < 7.2.3.1 Yes
Application f5 big-ip_access_policy_manager ≤ 13.1.5 Yes
Application f5 big-ip_access_policy_manager ≤ 14.1.5 Yes
Application f5 big-ip_access_policy_manager ≤ 15.1.8 Yes
Application f5 big-ip_access_policy_manager ≤ 16.1.3 Yes
Application f5 big-ip_access_policy_manager < 17.0.0.2 Yes
Application f5 big-ip_edge - Yes

References