Junglewise Threat Intelligence

CVE-2022-1388: F5 BIG-IP Missing Authentication Vulnerability

CVE-2022-1388 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-05-10

Technologies: F5 BIG-IP. Vendors: F5.

Executive brief

A missing authentication vulnerability in the F5 BIG-IP iControl REST interface allows unauthenticated attackers with network access to the BIG-IP system to execute arbitrary system commands, create or delete files, or disable services. This bypasses authentication via undisclosed requests.

Affected products

  • F5 BIG-IP 16.1.x prior to 16.1.2.2, 15.1.x prior to 15.1.5.1, 14.1.x prior to 14.1.4.6, 13.1.x prior to 13.1.5, 12.1.x, 11.6.x

Timeline

  • 2022-05-10: disclosed
  • 2022-05-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-10: patched: F5 released security advisory K23605346 and updates.

Related threats