CVE-2022-41617EPSS p61.4%
CVE-2022-41617CVE-2022-41617
f5 / big-ip_advanced_web_application_firewall
Description
In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, When the Advanced WAF / ASM module is provisioned, an authenticated remote code execution vulnerability exists in the BIG-IP iControl REST interface.
Scoring
| CVSS | 7.2 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 1.10% probability of exploitation · percentile 61.4% · 2026-06-18T12:00:27Z |
| Last modified | 2026-06-17 |