CVE-2022-1388

CVE Published 2022-05-05
Related CWE(s) CWE-306: Missing Authentication for Critical Function
Related Vendor(s) f5
Related Product(s) big-ip_policy_enforcement_manager, big-ip_domain_name_system, big-ip_fraud_protection_service, big-ip_application_security_manager, big-ip_application_acceleration_manager, big-ip_global_traffic_manager, big-ip_local_traffic_manager, big-ip_analytics, big-ip_advanced_firewall_manager, big-ip_link_controller, big-ip_access_policy_manager
Exploitation Reported (CISA KEV) 2022-05-10
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References