On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Is CVE-2022-1388 exploited?
Listed in the CISA KEV catalog on 2022-05-10.
Federal remediation due 2022-05-31.
Past that date by 1537 days.
Used in ransomware campaigns.
EPSS puts exploitation in the next 30 days at 100.0%.
Public exploit code: packaged in a public tool.
Public detection rules exist.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2022-1388
PlainSec has not published a story about this CVE.