peter bassill · operator
$ cve CVE-2022-1388 JSON

CVE-2022-1388 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-31.

Description

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.95% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-306
On CISA KEVyes — remediate by 2022-05-31
Public exploityes
Published2022-05-05
Last modified2026-06-17

CISA KEV

NameF5 BIG-IP Missing Authentication Vulnerability
Added2022-05-10
Due2022-05-31
Vendor / productF5 / BIG-IP
Ransomware useknown

Affected (11)

VendorProduct
f5big-ip access policy manager
f5big-ip advanced firewall manager
f5big-ip analytics
f5big-ip application acceleration manager
f5big-ip application security manager
f5big-ip domain name system
f5big-ip fraud protection service
f5big-ip global traffic manager
f5big-ip link controller
f5big-ip local traffic manager
f5big-ip policy enforcement manager

Public exploits

SourceTitleDate
exploit-dbF5 BIG-IP 16.0.x - Remote Code Execution (RCE)2022-05-12

References

→ the Explorer  ·  watch your stack  ·  NVD