← Back to CVE List
Vulnerability Intelligence Report
F5 BIG-IP Missing Authentication Vulnerability

CVE-2022-1388

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:99.96%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-306 ↗CWE-306 Missing Authentication for Critical Function

Affected Products & Versions

Vendor Product Affected Versions
F5 BIG-IP 17.0.0 < 17.0.x* (unaffected), 16.1.x < 16.1.2.2 (affected), 15.1.x < 15.1.5.1 (affected), 14.1.x < 14.1.4.6 (affected), 13.1.x < 13.1.5 (affected), 12.1.x <= 12.1.6 (affected), 11.6.x <= 11.6.5 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.956%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityF5, Inc. · Vendor · USA
Reserved2022-04-19T00:00:00
Published2022-05-05T16:18:04
Patch Date2022-05-04
Last Updated2025-10-21T23:15:40

LINK COPIED TO CLIPBOARD