← All CVEs

CVE-2022-1388

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-05-10Remediation due 2022-05-31

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

9.8
CVSS
100.0%
EPSS (exploit prob.)
100th
EPSS percentile
2022-05-05
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-306

Affected products

VendorProductAffected versions
f5big-ip_access_policy_manager>= 11.6.1, <= 11.6.5
f5big-ip_access_policy_manager>= 12.1.0, <= 12.1.6
f5big-ip_access_policy_manager>= 13.1.0, < 13.1.5
f5big-ip_access_policy_manager>= 14.1.0, < 14.1.4.6
f5big-ip_access_policy_manager>= 15.1.0, < 15.1.5.1
f5big-ip_access_policy_manager>= 16.1.0, < 16.1.2.2
f5big-ip_advanced_firewall_manager>= 11.6.1, <= 11.6.5
f5big-ip_advanced_firewall_manager>= 12.1.0, <= 12.1.6
f5big-ip_advanced_firewall_manager>= 13.1.0, < 13.1.5
f5big-ip_advanced_firewall_manager>= 14.1.0, < 14.1.4.6
f5big-ip_advanced_firewall_manager>= 15.1.0, < 15.1.5.1
f5big-ip_advanced_firewall_manager>= 16.1.0, < 16.1.2.2
f5big-ip_analytics>= 11.6.1, <= 11.6.5
f5big-ip_analytics>= 12.1.0, <= 12.1.6
f5big-ip_analytics>= 13.1.0, < 13.1.5
f5big-ip_analytics>= 14.1.0, < 14.1.4.6
f5big-ip_analytics>= 15.1.0, < 15.1.5.1
f5big-ip_analytics>= 16.1.0, < 16.1.2.2
f5big-ip_application_acceleration_manager>= 11.6.1, <= 11.6.5
f5big-ip_application_acceleration_manager>= 12.1.0, <= 12.1.6
f5big-ip_application_acceleration_manager>= 13.1.0, < 13.1.5
f5big-ip_application_acceleration_manager>= 14.1.0, < 14.1.4.6
f5big-ip_application_acceleration_manager>= 15.1.0, < 15.1.5.1
f5big-ip_application_acceleration_manager>= 16.1.0, < 16.1.2.2
f5big-ip_application_security_manager>= 11.6.1, <= 11.6.5
f5big-ip_application_security_manager>= 12.1.0, <= 12.1.6
f5big-ip_application_security_manager>= 13.1.0, < 13.1.5
f5big-ip_application_security_manager>= 14.1.0, < 14.1.4.6
f5big-ip_application_security_manager>= 15.1.0, < 15.1.5.1
f5big-ip_application_security_manager>= 16.1.0, < 16.1.2.2
f5big-ip_domain_name_system>= 11.6.1, <= 11.6.5
f5big-ip_domain_name_system>= 12.1.0, <= 12.1.6
f5big-ip_domain_name_system>= 13.1.0, < 13.1.5
f5big-ip_domain_name_system>= 14.1.0, < 14.1.4.6
f5big-ip_domain_name_system>= 15.1.0, < 15.1.5.1
f5big-ip_domain_name_system>= 16.1.0, < 16.1.2.2
f5big-ip_fraud_protection_service>= 11.6.1, <= 11.6.5
f5big-ip_fraud_protection_service>= 12.1.0, <= 12.1.6
f5big-ip_fraud_protection_service>= 13.1.0, < 13.1.5
f5big-ip_fraud_protection_service>= 14.1.0, < 14.1.4.6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-1388