cbcvebase.
CVE-2022-1388
published 2022-05-05

CVE-2022-1388: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all…

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-31
Exploited in the wild
EPSS
99.96%
100.0th percentile
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Affected

84 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip11.6.x – 11.6.5
f5big-ip12.1.x – 12.1.6
f5big-ip>= 13.1.x < 13.1.513.1.5
f5big-ip>= 14.1.x < 14.1.4.614.1.4.6
f5big-ip>= 15.1.x < 15.1.5.115.1.5.1
f5big-ip>= 16.1.x < 16.1.2.216.1.2.2
f5big-ip_aam
f5big-ip_access_policy_manager11.6.1 – 11.6.5
f5big-ip_access_policy_manager12.1.0 – 12.1.6
f5big-ip_access_policy_manager>= 13.1.0 < 13.1.513.1.5
f5big-ip_access_policy_manager>= 14.1.0 < 14.1.4.614.1.4.6
f5big-ip_access_policy_manager>= 15.1.0 < 15.1.5.115.1.5.1
f5big-ip_access_policy_manager>= 16.1.0 < 16.1.2.216.1.2.2
f5big-ip_advanced_firewall_manager11.6.1 – 11.6.5
f5big-ip_advanced_firewall_manager12.1.0 – 12.1.6
f5big-ip_advanced_firewall_manager>= 13.1.0 < 13.1.513.1.5
f5big-ip_advanced_firewall_manager>= 14.1.0 < 14.1.4.614.1.4.6
f5big-ip_advanced_firewall_manager>= 15.1.0 < 15.1.5.115.1.5.1
f5big-ip_advanced_firewall_manager>= 16.1.0 < 16.1.2.216.1.2.2
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics11.6.1 – 11.6.5
f5big-ip_analytics12.1.0 – 12.1.6
f5big-ip_analytics>= 13.1.0 < 13.1.513.1.5
f5big-ip_analytics>= 14.1.0 < 14.1.4.614.1.4.6

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.