Vulnerability record · CVE-2022-1388 · published 5 May 2022
CVE-2022-1388: F5 BIG-IP iControl REST authentication bypass
F5 · Big Ip Access Policy Manager
Undisclosed requests to the iControl REST interface on multiple F5 BIG-IP modules can bypass authentication, allowing an unauthenticated remote attacker to reach critical functions. The flaw affects 16.1.x before 16.1.2.2, 15.1.x before 15.1.5.1, 14.1.x before 14.1.4.6, 13.1.x before 13.1.5, and all 12.1.x and 11.6.x releases. Because BIG-IP sits at the network edge and manages traffic, compromise has broad downstream impact.
Description
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution on edge devices, near-maximum EPSS, public exploits and CISA KEV listing with ransomware use make this an urgent patch.
What it is
Undisclosed requests to the iControl REST interface on multiple F5 BIG-IP modules can bypass authentication, allowing an unauthenticated remote attacker to reach critical functions. The flaw affects 16.1.x before 16.1.2.2, 15.1.x before 15.1.5.1, 14.1.x before 14.1.4.6, 13.1.x before 13.1.5, and all 12.1.x and 11.6.x releases. Because BIG-IP sits at the network edge and manages traffic, compromise has broad downstream impact.
Impact
An attacker gains unauthenticated access to iControl REST and, per public exploit references, can achieve remote code execution on the BIG-IP system. That yields full control of the device, including configuration, traffic handling and any secrets it holds.
Attack surface
Reachable over the network via the iControl REST interface; the CVSS vector shows no privileges and no user interaction required. Any BIG-IP management interface exposed to untrusted networks is directly at risk.
Exploitation
Listed in CISA KEV with a due date of 2022-05-31 and flagged for known ransomware campaign use, and EPSS is near 1.0 (0.99958). Multiple public exploit references exist, so exploitation is active and widespread.
What to do
- Upgrade to a fixed release: 16.1.2.2, 15.1.5.1, 14.1.4.6 or 13.1.5; 12.1.x and 11.6.x are unsupported and must be migrated off.
- If immediate patching is not possible, apply F5's K23605346 mitigation, which restricts iControl REST access to trusted networks.
- Block or restrict management and iControl REST access from the internet; place it behind a management network or jump host.
- Rotate credentials and secrets stored on any BIG-IP that may have been exposed, and review configuration for unauthorized changes.
- Monitor F5 advisories and CISA KEV for updates, and treat unsupported versions as permanently exposed.
Detection
- Audit iControl REST access logs for requests from unexpected source IPs or at unusual times, especially to /mgmt/ endpoints.
- Alert on creation of new administrative accounts, tokens or configuration changes on BIG-IP devices.
- Hunt for known exploit request patterns against iControl REST in web/proxy logs and IDS/IPS signatures.
- Correlate BIG-IP outbound connections or process execution anomalies that could indicate post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-1388 to the Known Exploited Vulnerabilities catalog on 10 May 2022 as "F5 BIG-IP Missing Authentication Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 31 May 2022.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-1388 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-1388), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.