On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HF5 Big Ip Access Policy Manager
APPF511.6.1 – 11.6.512.1.0 – 12.1.613.1.0 – 13.1.5 (excl.)14.1.0 – 14.1.4.6 (excl.)15.1.0 – 15.1.5.1 (excl.)16.1.0 – 16.1.2.2 (excl.)F5 Big Ip Advanced Firewall Manager
APPF511.6.1 – 11.6.512.1.0 – 12.1.613.1.0 – 13.1.5 (excl.)14.1.0 – 14.1.4.6 (excl.)15.1.0 – 15.1.5.1 (excl.)16.1.0 – 16.1.2.2 (excl.)F5 Big Ip Analytics
APPF511.6.1 – 11.6.512.1.0 – 12.1.613.1.0 – 13.1.5 (excl.)14.1.0 – 14.1.4.6 (excl.)15.1.0 – 15.1.5.1 (excl.)16.1.0 – 16.1.2.2 (excl.)F5 Big Ip Application Acceleration Manager
APPF511.6.1 – 11.6.512.1.0 – 12.1.613.1.0 – 13.1.5 (excl.)14.1.0 – 14.1.4.6 (excl.)15.1.0 – 15.1.5.1 (excl.)16.1.0 – 16.1.2.2 (excl.)F5 Big Ip Application Security Manager
APPF511.6.1 – 11.6.512.1.0 – 12.1.613.1.0 – 13.1.5 (excl.)14.1.0 – 14.1.4.6 (excl.)15.1.0 – 15.1.5.1 (excl.)16.1.0 – 16.1.2.2 (excl.)F5 Big Ip Domain Name System
APPF511.6.1 – 11.6.512.1.0 – 12.1.613.1.0 – 13.1.5 (excl.)14.1.0 – 14.1.4.6 (excl.)15.1.0 – 15.1.5.1 (excl.)16.1.0 – 16.1.2.2 (excl.)F5 Big Ip Fraud Protection Service
APPF511.6.1 – 11.6.512.1.0 – 12.1.613.1.0 – 13.1.5 (excl.)14.1.0 – 14.1.4.6 (excl.)15.1.0 – 15.1.5.1 (excl.)16.1.0 – 16.1.2.2 (excl.)F5 Big Ip Global Traffic Manager
APPF511.6.1 – 11.6.512.1.0 – 12.1.613.1.0 – 13.1.5 (excl.)14.1.0 – 14.1.4.6 (excl.)15.1.0 – 15.1.5.1 (excl.)16.1.0 – 16.1.2.2 (excl.)F5 Big Ip Link Controller
APPF511.6.1 – 11.6.512.1.0 – 12.1.613.1.0 – 13.1.5 (excl.)14.1.0 – 14.1.4.6 (excl.)15.1.0 – 15.1.5.1 (excl.)16.1.0 – 16.1.2.2 (excl.)F5 Big Ip Local Traffic Manager
APPF511.6.1 – 11.6.512.1.0 – 12.1.613.1.0 – 13.1.5 (excl.)14.1.0 – 14.1.4.6 (excl.)15.1.0 – 15.1.5.1 (excl.)16.1.0 – 16.1.2.2 (excl.)F5 Big Ip Policy Enforcement Manager
APPF511.6.1 – 11.6.512.1.0 – 12.1.613.1.0 – 13.1.5 (excl.)14.1.0 – 14.1.4.6 (excl.)15.1.0 – 15.1.5.1 (excl.)16.1.0 – 16.1.2.2 (excl.)
CISA KEV — detailsi
- Vendori
- F5 ↗
- Producti
- BIG-IP
- Added to KEVi
- May 10, 2022
- Remediation deadline (US Federal)i
- May 31, 2022(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply updates per vendor instructions.
F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.
Related vulnerabilities
RCE w F5 BIG-IP APM poprzez złośliwy ruch sieciowy (stack buffer overflow)
F5 BIG-IP: Obejście uwierzytelnienia i zdalne wykonanie poleceń (RCE)
Buffer overflow w TMM URI normalization F5 BIG-IP — DoS/RCE
F5 BIG-IP/BIG-IQ iControl REST — nieuwierzytelniony RCE
F5 BIG-IP TMUI — krytyczny RCE przez path traversal (CVE-2020-5902)