On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Is CVE-2022-1388 exploited?
Listed in the CISA KEV catalog on 2022-05-10.
Federal remediation due 2022-05-31.
Past that date by 1584 days.
Used in ransomware campaigns.
EPSS puts exploitation in the next 30 days at 100.0%.