CVE-2022-1388: F5 BIG-IP Missing Authentication Vulnerability
F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.
Other sources
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
F5 BIG-IPto a version that resolves this vulnerability.Fixed in 16.1.2.2 - Upgrade
Upgrade
F5 BIG-IPto a version that resolves this vulnerability.Fixed in 15.1.5.1 - Upgrade
Upgrade
F5 BIG-IPto a version that resolves this vulnerability.Fixed in 14.1.4.6 - Upgrade
Upgrade
F5 BIG-IPto a version that resolves this vulnerability.Fixed in 13.1.5 - Compensating control
For deployments running 12.1.x or 11.6.x (all versions are indicated vulnerable), restrict access to the iControl REST management interface to trusted management networks and specific IP addresses (block access from untrusted networks/internet) until a supported, fixed version is available or the device is upgraded.
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1388?
CVE-2022-1388 is classified as a critical vulnerability with a high risk of remote code execution, allowing attackers to manipulate files and disable services.
How do I fix CVE-2022-1388?
To remediate CVE-2022-1388, you should upgrade F5 BIG-IP software to the versions specified in the security advisory, specifically 16.1.2.2 or later for 16.1.x, 15.1.5.1 or later for 15.1.x, and so on.
What are the affected versions of F5 BIG-IP related to CVE-2022-1388?
CVE-2022-1388 affects several F5 BIG-IP versions, including 16.1.x prior to 16.1.2.2, 15.1.x prior to 15.1.5.1, and 14.1.x versions prior to specified versions.
Can CVE-2022-1388 be exploited by unauthenticated users?
Yes, CVE-2022-1388 can be exploited by unauthenticated users, enabling remote code execution without requiring valid credentials.
What are the potential impacts of CVE-2022-1388?
The vulnerability CVE-2022-1388 can lead to severe consequences such as remote code execution, unauthorized file manipulation, and service disruptions.