CVE-2022-1388

Scores

EPSS

0.945High94.5%
0%20%40%60%80%100%

Percentile: 94.5%

CVSS

9.8Critical3.x
0246810

CVSS Score: 9.8/10

All CVSS Scores

CVSS 3.x
9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Description

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-306

Related Vulnerabilities

Exploits

Exploit ID: 50932

Source: exploitdb

URL: https://www.exploit-db.com/exploits/50932

Exploit ID: CVE-2022-1388

Source: github-poc

URL: https://github.com/impost0r/CVE-2022-1388

Vulnerable Software (11)

Type: Configuration

Vendor: f5

Product: big-ip_access_policy_manager

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
      "versionEndIncluding": "11.6.5",
      "versionStartIncluding": "11.6.1",
      "vulnerabl...

Source: nvd

Type: Configuration

Vendor: f5

Product: big-ip_advanced_firewall_manager

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
      "versionEndIncluding": "11.6.5",
      "versionStartIncluding": "11.6.1",
      "vulnerabl...

Source: nvd

Type: Configuration

Vendor: f5

Product: big-ip_analytics

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
      "versionEndIncluding": "11.6.5",
      "versionStartIncluding": "11.6.1",
      "vulnerabl...

Source: nvd

Type: Configuration

Vendor: f5

Product: big-ip_application_acceleration_manager

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
      "versionEndIncluding": "11.6.5",
      "versionStartIncluding": "11.6.1",
      "vulnerabl...

Source: nvd

Type: Configuration

Vendor: f5

Product: big-ip_application_security_manager

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
      "versionEndIncluding": "11.6.5",
      "versionStartIncluding": "11.6.1",
      "vulnerabl...

Source: nvd

Type: Configuration

Vendor: f5

Product: big-ip_domain_name_system

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
      "versionEndIncluding": "11.6.5",
      "versionStartIncluding": "11.6.1",
      "vulnerabl...

Source: nvd

Type: Configuration

Vendor: f5

Product: big-ip_fraud_protection_service

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
      "versionEndIncluding": "11.6.5",
      "versionStartIncluding": "11.6.1",
      "vulnerabl...

Source: nvd

Type: Configuration

Vendor: f5

Product: big-ip_global_traffic_manager

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
      "versionEndIncluding": "11.6.5",
      "versionStartIncluding": "11.6.1",
      "vulnerabl...

Source: nvd

Type: Configuration

Vendor: f5

Product: big-ip_link_controller

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
      "versionEndIncluding": "11.6.5",
      "versionStartIncluding": "11.6.1",
      "vulnerabl...

Source: nvd

Type: Configuration

Vendor: f5

Product: big-ip_local_traffic_manager

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*",
      "versionEndIncluding": "11.6.5",
      "versionStartIncluding": "11.6.1",
      "vulnerabl...

Source: nvd