CVE-2022-1388
F5 BIG-IP
Published 5 May 2022 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, f5.com
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 10 May 2022, with a remediation deadline of 31 May 2022 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply updates per vendor instructions.
Description
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
References
- packetstormsecurity.com/files/167007/F5-BIG-IP-Remote-Code-Execution.html · Exploit, Third Party Advisory, VDB Entry
- packetstormsecurity.com/files/167118/F5-BIG-IP-16.0.x-Remote-Code-Execution.html · Exploit, Third Party Advisory, VDB Entry
- packetstormsecurity.com/files/167150/F5-BIG-IP-iControl-Remote-Code-Execution.html · Exploit, Third Party Advisory, VDB Entry
- support.f5.com/csp/article/K23605346 · Mitigation, Vendor Advisory
- www.secpod.com/blog/critical-f5-big-ip-remote-code-execution-vulnerability-patch-now/ · Exploit, Mitigation, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-1388 · US Government Resource