CVE-2022-27662
CVE-2022-27662 is a medium-severity vulnerability in F5 Traffix Signaling Delivery Controller with a CVSS 3.x base score of 4.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1336.
Key facts
- Severity: Medium (CVSS 3.x base score 4.8)
- CVSS v2: 3.5
- EPSS exploit prediction: 0% (39th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-1336
- Affected product: F5 Traffix Signaling Delivery Controller
- Published:
- Last modified:
Description
On F5 Traffix SDC 5.2.x versions prior to 5.2.2 and 5.1.x versions prior to 5.1.35, a stored Cross-Site Template Injection vulnerability exists in an undisclosed page of the Traffix SDC Configuration utility that allows an attacker to execute template language-specific instructions in the context of the server. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Frequently asked questions
- What is CVE-2022-27662?
- On F5 Traffix SDC 5.2.x versions prior to 5.2.2 and 5.1.x versions prior to 5.1.35, a stored Cross-Site Template Injection vulnerability exists in an undisclosed page of the Traffix SDC Configuration utility that allows an attacker to execute template language-specific instructions in the context of the server. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
- How severe is CVE-2022-27662?
- CVE-2022-27662 has a CVSS 3.x base score of 4.8, rated medium severity. It is exploitable over network with low attack complexity, requires high privileges and user interaction. Impact on confidentiality is low, integrity low, and availability none.
- Is CVE-2022-27662 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (39th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2022-27662?
- CVE-2022-27662 primarily affects F5 Traffix Signaling Delivery Controller. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2022-27662?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2022-27662 published?
- CVE-2022-27662 was published on 2022-05-05 and last updated on 2026-06-17.
References
Affected products (2)
- cpe:2.3:a:f5:traffix_signaling_delivery_controller:5.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:f5:traffix_signaling_delivery_controller:5.2.0:*:*:*:*:*:*:*
More vulnerabilities in F5 Traffix Signaling Delivery Controller
- CVE-2014-7169 — Critical (CVSS 9.8): GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values…
- CVE-2014-6271 — Critical (CVSS 9.8): GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables,…
- CVE-2018-20836 — High (CVSS 8.1): An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and…
- CVE-2019-5436 — High (CVSS 7.8): A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4…
- CVE-2019-9077 — High (CVSS 7.8): An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_specific in readelf.c…
- CVE-2019-9070 — High (CVSS 7.8): An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a heap-based buffer over-read in…
All CVEs affecting F5 Traffix Signaling Delivery Controller →
Other CWE-1336 vulnerabilities
- CVE-2026-48323 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine…
- CVE-2026-44181 — Critical (CVSS 10.0): Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark,…
- CVE-2025-53833 — Critical (CVSS 10.0): LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior…
- CVE-2024-32651 — Critical (CVSS 10.0): changedetection.io is an open source web page change detection, website watcher, restock monitor and notification…
- CVE-2026-65974 — Critical (CVSS 9.9): ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited…
- CVE-2026-72911 — Critical (CVSS 9.9): ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the…