EXPOSURES › CVE-2022-1388
CVE-2022-1388
CRITICAL ⌖ ON CISA KEV · EXPLOITEDF5 BIG-IP's missing authentication allowed remote code execution and service disruption, actively exploited in ransomware attacks.
A critical vulnerability in F5 BIG-IP allowed unauthorized access and control, enabling remote code execution and potentially disrupting services; DIB organizations using BIG-IP must immediately patch and review access controls to avoid compromise and maintain CMMC compliance.
Shame score — The vulnerability's critical severity and active exploitation by ransomware groups highlights a significant failure in authentication design and security practices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.