Vulnerability record · CVE-2022-41622 · published 7 December 2022
CVE-2022-41622: F5 BIG-IP and BIG-IQ iControl SOAP CSRF flaw
F5 · Big Iq Centralized Management
BIG-IP and BIG-IQ are vulnerable to cross-site request forgery through the iControl SOAP interface across all versions, per the vendor description. Because the interface is reachable over the network and the flaw allows state-changing requests, it matters for any deployment exposing iControl SOAP.
Description
In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with no privileges required and a very high EPSS score, though exploitation requires user interaction and no KEV listing exists.
What it is
BIG-IP and BIG-IQ are vulnerable to cross-site request forgery through the iControl SOAP interface across all versions, per the vendor description. Because the interface is reachable over the network and the flaw allows state-changing requests, it matters for any deployment exposing iControl SOAP.
Impact
An attacker who lures a privileged user into a crafted request can trigger unauthorized actions through iControl SOAP with that user's privileges, affecting confidentiality, integrity and availability (CVSS 8.8).
Attack surface
Reached over the network via the iControl SOAP endpoint; the CVSS vector shows no privileges required but user interaction is required, so a victim with an active session must be induced to send the request.
Exploitation
Not listed in CISA KEV and no public exploit tags appear in the references, but EPSS is very high (0.9234, 99.8th percentile), indicating elevated predicted exploitation activity.
What to do
- Apply the F5 vendor advisory K94221585 fixes for BIG-IP and BIG-IQ; note that EoTS versions are not evaluated and should be upgraded or retired.
- Restrict network access to iControl SOAP to trusted management hosts and disable it where not needed.
- Enforce same-site cookies and CSRF protections on management interfaces, and avoid browsing untrusted sites while authenticated to the management UI.
- Monitor and alert on unexpected iControl SOAP configuration changes.
Detection
- Audit iControl SOAP access logs for requests originating from unexpected client IPs or referers.
- Alert on configuration or object changes made via iControl SOAP outside change windows.
- Correlate management UI sessions with SOAP calls to spot cross-origin request patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.f5.com/csp/article/K94221585 | Vendor Advisory |
| https://support.f5.com/csp/article/K94221585 | Vendor Advisory |
Track CVE-2022-41622 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-41622), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.