← Vulnerability feed

Vulnerability record · CVE-2022-41622 · published 7 December 2022

CVE-2022-41622: F5 BIG-IP and BIG-IQ iControl SOAP CSRF flaw

F5 · Big Iq Centralized Management

BIG-IP and BIG-IQ are vulnerable to cross-site request forgery through the iControl SOAP interface across all versions, per the vendor description. Because the interface is reachable over the network and the flaw allows state-changing requests, it matters for any deployment exposing iControl SOAP.

8.8 CVSS 3.1 High EPSS 92% · top 0.2% CWE-352 · Cross-site request forgery
8.8CVSS 3.1 base score
92%EPSS exploitation probability, 30 days
NoNot in CISA KEV
12Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In all versions,  BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 8.8 with no privileges required and a very high EPSS score, though exploitation requires user interaction and no KEV listing exists.

What it is

BIG-IP and BIG-IQ are vulnerable to cross-site request forgery through the iControl SOAP interface across all versions, per the vendor description. Because the interface is reachable over the network and the flaw allows state-changing requests, it matters for any deployment exposing iControl SOAP.

Impact

An attacker who lures a privileged user into a crafted request can trigger unauthorized actions through iControl SOAP with that user's privileges, affecting confidentiality, integrity and availability (CVSS 8.8).

Attack surface

Reached over the network via the iControl SOAP endpoint; the CVSS vector shows no privileges required but user interaction is required, so a victim with an active session must be induced to send the request.

Exploitation

Not listed in CISA KEV and no public exploit tags appear in the references, but EPSS is very high (0.9234, 99.8th percentile), indicating elevated predicted exploitation activity.

What to do

  • Apply the F5 vendor advisory K94221585 fixes for BIG-IP and BIG-IQ; note that EoTS versions are not evaluated and should be upgraded or retired.
  • Restrict network access to iControl SOAP to trusted management hosts and disable it where not needed.
  • Enforce same-site cookies and CSRF protections on management interfaces, and avoid browsing untrusted sites while authenticated to the management UI.
  • Monitor and alert on unexpected iControl SOAP configuration changes.

Detection

  • Audit iControl SOAP access logs for requests originating from unexpected client IPs or referers.
  • Alert on configuration or object changes made via iControl SOAP outside change windows.
  • Correlate management UI sessions with SOAP calls to spot cross-origin request patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-41622 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-46747F5 BIG-IP configuration utility authentication bypass allows command executionUndisclosed requests can bypass authentication in the BIG-IP configuration utility, letting a network-positioned attacker execute arbitrary system co…KEVEPSS 97%analysed9.8CVE-2022-1388F5 BIG-IP iControl REST authentication bypassUndisclosed requests to the iControl REST interface on multiple F5 BIG-IP modules can bypass authentication, allowing an unauthenticated remote attac…KEVEPSS 100%analysed9.8CVE-2021-22991F5 BIG-IP TMM URI normalization buffer overflowF5 BIG-IP's Traffic Management Microkernel (TMM) mishandles URI normalization for undisclosed requests to a virtual server, triggering a buffer overf…KEVEPSS 61%analysed9.8CVE-2021-22986F5 BIG-IP iControl REST unauthenticated remote command executionThe iControl REST interface on multiple F5 BIG-IP and BIG-IQ versions exposes an unauthenticated remote command execution flaw, tracked as CWE-918 se…KEVEPSS 100%analysed9.8CVE-2020-5902F5 BIG-IP TMUI path traversal leading to remote code executionThe F5 BIG-IP Traffic Management User Interface (TMUI, also called the Configuration utility) contains a path traversal flaw (CWE-22) in undisclosed …KEVEPSS 100%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed9.3CVE-2026-94127F5 big-ip access policy manager heap-based buffer overflow vulnerabilityWhen a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution…KEVEPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2022-41622), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.