Executive brief
A missing authentication vulnerability in the F5 BIG-IP iControl REST interface allows unauthenticated attackers with network access to the BIG-IP system to execute arbitrary system commands, create or delete files, or disable services. This bypasses authentication via undisclosed requests.
Affected products
- F5 BIG-IP 16.1.x prior to 16.1.2.2, 15.1.x prior to 15.1.5.1, 14.1.x prior to 14.1.4.6, 13.1.x prior to 13.1.5, 12.1.x, 11.6.x
Timeline
- 2022-05-10: disclosed
- 2022-05-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-05-10: patched: F5 released security advisory K23605346 and updates.