F5 BIG-IP RCE Vulnerability CVE-2022-1388
ID: 00afa920-dcc0-5f39-a919-962a0ad55a6a
STIX ID: report--00afa920-dcc0-5f39-a919-962a0ad55a6a
Feed Name: Cyble Blog
This report documents CVE-2022-1388, a critical (CVSSv3 9.8) authentication bypass in F5 BIG-IP iControl REST that allows unauthenticated remote code execution by abusing Connection header behavior to remove X-F5-Auth-Token; it details the technical root cause, affected/fixed versions, evidence of active exploitation (public PoCs, scanning, tweets, darkweb postings), observed payloads (coin miners, GhostRat, Perlbot), lists hashes and IP IOCs, and recommends immediate patching and restricting management-interface access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
