CVE-2022-1388

Confirmed PUBLISHED

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to...

F5 · BIG-IP
Exploited in the wild Used in malware PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical EPSS 100.0%

At a Glance

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

ransomware nuclei_scanner cisa malware edge metasploit
CVE Published
May 05, 2022
Exploitation Reported
May 10, 2022
CVSS
9.8 Critical
EPSS
100.0%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
F5
BIG-IP

17.0.0 to < 17.0.x*

Unaffected
F5
BIG-IP

16.1.x to < 16.1.2.2

Affected
F5
BIG-IP

15.1.x to < 15.1.5.1

Affected
F5
BIG-IP

14.1.x to < 14.1.4.6

Affected
F5
BIG-IP

13.1.x to < 13.1.5

Affected
F5
BIG-IP

12.1.x to <= 12.1.6

Affected
F5
BIG-IP

11.6.x to <= 11.6.5

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.