Missing Authentication for Critical Function in BIG-IP - CVE-2022-1388
Published: May 10, 2022 / Updated: January 7, 2024
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to missing authentication in iControl REST API at "/mgmt/tm/util/bash". A remote non-authenticated attacker can send a specially crafted HTTP POST request to the management port and/or self IP addresses and execute arbitrary commands on the system.
Successful exploitation of the vulnerability may result in full system compromise.
Affected software
How to mitigate CVE-2022-1388
Links to Public Exploits and PoC-codes
- Exploit #9489 - CVE-2022-1388-exploit (exploit poc) (January 7, 2024)
- Exploit #8987 - CVE-2022-1388-EXP (CVE-2022-1388 F5 BIG-IP RCE 批量检测) (April 16, 2023)
- Exploit #8698 - CVE-2022-1388 (-- FOR EDUCATIONAL USE ONLY -- Proof-of-Concept RCE for CVE-2022-1388, plus some added functionality for blue and red teams) (December 27, 2022)
- Exploit #8690 - CVE-2022-1388 () (December 22, 2022)
- Exploit #8660 - CVE-2022-1388 (Scan IP ranges for IP's vulnerable to the F5 Big IP exploit (CVE-2022-1388)) (December 11, 2022)
- Exploit #8654 - CVE-2022-1388 () (December 7, 2022)
- Exploit #8640 - CVE-2022-1388 () (November 30, 2022)
- Exploit #8538 - CVE-2022-1388 (cURL one-liner to test for CVE-2022-1388 BIG-IP iControl REST RCE) (October 26, 2022)
- Exploit #8537 - CVE-2022-1388 (cURL one-liner to test for CVE-2022-1388 BIG-IP iControl REST RCE) (October 26, 2022)
- Exploit #8426 - CVE-2022-1388-RCE-checker () (October 2, 2022)
- Exploit #8106 - CVE-2022-1388 (CVE-2022-1388, bypassing iControl REST authentication) (July 4, 2022)
- Exploit #8104 - CVE-2022-1388_refresh (PoC for exploiting CVE-2022-1388 on BIG IP F5) (July 3, 2022)
- Exploit #8074 - Mass-CVE-2022-1388 (Mass-Exploit-CVE-2022-1388) (June 24, 2022)
- Exploit #7915 - F5-CVE-2022-1388-Exploit () (May 29, 2022)
- Exploit #7914 - Exploit-F5-CVE-2022-1388 () (May 29, 2022)
- Exploit #7913 - CVE-2022-1388-PocExp () (May 29, 2022)
- Exploit #7909 - F5-BIG-IP-POC (CVE-2020-5902 CVE-2021-22986 CVE-2022-1388 POC集合) (May 29, 2022)
- Exploit #7855 - F5-BIG-IP-exploit (CVE-2022-1388) (May 17, 2022)
- Exploit #7854 - CVE-2022-1388-rs (CVE-2022-1388 F5 BIG-IP iControl REST Auth Bypass RCE written in Rust) (May 17, 2022)
- Exploit #7844 - CVE-2022-1388-POC (An Improved Proof of Concept for CVE-2022-1388 w/ an Interactive Shell) (May 16, 2022)
- Exploit #7840 - CVE-2022-1388 (Tool for CVE-2022-1388 ) (May 16, 2022)
- Exploit #7838 - CVE-2022-1388-Exploit-POC (PoC for CVE-2022-1388_F5_BIG-IP) (May 16, 2022)
- Exploit #7837 - cve-2022-1388-iveresk-command-shell (Improved POC for CVE-2022-1388 that affects multiple F5 products.) (May 16, 2022)
- Exploit #7831 - F5 BIG-IP 16.0.x - Remote Code Execution (RCE) (May 14, 2022)
- Exploit #7793 - CVE-2022-1388 (Research and proof of concept related to CVE-2022-1388.) (May 12, 2022)
- Exploit #7789 - F5 BIG-IP iControl RCE via REST Authentication Bypass (May 12, 2022)
- Exploit #7763 - F5-BIG-IP-RCE-Check (CVE-2022-1388 F5 BIG-IP iControl Rest API exposed RCE Check) (May 11, 2022)
- Exploit #7762 - CVE-2022-1388-RCE-checker () (May 11, 2022)
- Exploit #7761 - CVE-2022-1388_F5_BIG-IP (PoC for CVE-2022-1388_F5_BIG-IP) (May 11, 2022)
- Exploit #7760 - CVE-2022-1388-checker (Simple script realizado en bash, para revisión de múltiples hosts para CVE-2022-1388 (F5)) (May 11, 2022)
- Exploit #7759 - CVE-2022-1388 (CVE-2022-1388 F5 BIG-IP iControl REST身份验证绕过漏洞) (May 11, 2022)
- Exploit #7758 - CVE-2022-1388 (batch scan CVE-2022-1388) (May 11, 2022)
- Exploit #7757 - CVE-2022-1388 (CVE-2022-1388) (May 11, 2022)
- Exploit #7756 - CVE-2022-1388 () (May 11, 2022)
- Exploit #7755 - CVE-2022-1388 (POC of CVE-2022-1388) (May 11, 2022)
- Exploit #7754 - F5-BIG-IP-RCE-CVE-2022-1388 () (May 11, 2022)
- Exploit #7753 - cve-2022-1388-1veresk (Simple shell script for the exploit) (May 11, 2022)
- Exploit #7752 - CVE-2022-1388-F5-BIG-IP () (May 11, 2022)
- Exploit #7751 - CVE-2022-1388-EXP (CVE-2022-1388-EXP可批量实现攻击) (May 11, 2022)
- Exploit #7750 - CVE-2022-1388-Exploit (Test and Exploit Scripts for CVE 2022-1388 (F5 Big-IP)) (May 11, 2022)
- Exploit #7749 - CVE2022-1388_TestAPI (A Test API for testing the POC against CVE-2022-1388) (May 11, 2022)
- Exploit #7748 - CVE-2022-1388-PocExp (CVE-2022-1388-PocExp,新增了多线程,F5 BIG-IP RCE exploitation) (May 11, 2022)
- Exploit #7746 - CVE-2022-1388 (CVE-2022-1388 POC exploit) (May 11, 2022)
- Exploit #7745 - F5-BigIP-CVE-2022-1388 (Reverse Shell for CVE-2022-1388) (May 11, 2022)
- Exploit #7744 - CVE-2022-1388 (CVE-2022-1388_goby_pocsuite3) (May 11, 2022)
- Exploit #7742 - CVE-2022-1388_F5_BIG-IP_RCE (PoC for CVE-2022-1388_F5_BIG-IP) (May 11, 2022)
- Exploit #7741 - CVE-2022-1388 (CVE-2022-1388 Scanner) (May 11, 2022)
- Exploit #7740 - CVE-2022-1388 (CVE-2022-1388) (May 11, 2022)
- Exploit #7739 - CVE-2022-1388 (CVE-2022-1388 F5 BIG-IP iControl REST Auth Bypass RCE) (May 11, 2022)
- Exploit #7738 - CVE-2022-1388-EXP (CVE-2022-1388 F5 BIG-IP RCE 批量检测) (May 11, 2022)
- Exploit #7737 - CVE-2022-1388 () (May 11, 2022)
- Exploit #7736 - CVE-2022-1388 (This repository consists of the python exploit for CVE-2022-1388 (F5's BIG-IP Authentication Bypass to RCE) ) (May 11, 2022)
- Exploit #7734 - CVE-2022-1388 (BIG-IP iControl REST vulnerability CVE-2022-1388 PoC) (May 11, 2022)
- Exploit #7733 - CVE-2022-1388-RCE-checker-and-POC-Exploit () (May 11, 2022)
- Exploit #7732 - CVE-2022-1388-Scanner () (May 11, 2022)
- Exploit #7731 - CVE-2022-1388_PoC (F5 BIG-IP RCE exploitation (CVE-2022-1388)) (May 10, 2022)
- Exploit #7730 - CVE-2022-1388 (F5 BIG-IP iControl REST身份验证绕过漏洞) (May 10, 2022)
- Exploit #7729 - F5-Big-IP-CVE-2022-1388 (CVE-2022-1388 F5 Big IP unauth remote code execution) (May 10, 2022)
- Exploit #7728 - CVE-2022-1388 (CVE-2022-1388 F5 BIG-IP iControl REST RCE) (May 10, 2022)
- Exploit #7727 - Exploit-F5-CVE-2022-1388 (PoC For F5 BIG-IP - bash script Exploit one Liner) (May 10, 2022)
- Exploit #7726 - Nuclei-Template-Exploit-F5-BIG-IP-iControl-REST-Auth-Bypass-RCE-Command-Parameter (CVE-2022-1388 is an authentication bypass vulnerability in the REST component of BIG-IP’s iControl API that was assigned a CVSSv3 score of 9.8. The iControl REST (May 10, 2022)
- Exploit #7725 - CVE-2022-1388 (POC for CVE-2022-1388) (May 10, 2022)