LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-1388: F5 BIG-IP Missing Authentication Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 10, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 31, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-1388 to its Known Exploited Vulnerabilities catalog on May 10, 2022, with a federal patch deadline of May 31, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.

CVE-2022-1388 is a missing-authentication vulnerability in F5 BIG-IP. An unauthenticated attacker who can reach a vulnerable management interface may execute code, create or delete files, or disable services. Because the flaw has been used in ransomware activity, organizations running BIG-IP should treat exposure as high priority and confirm exact impact against the vendor advisory.

CISA lists the required action as applying updates per vendor instructions. The remainder of this guidance focuses on practical detection, remediation, and interim controls for IT and security teams.

How it works

The weakness is classified as CWE-306: Missing Authentication for Critical Function. In products of this class, a management or control-plane function that should require authentication can be invoked without valid credentials when certain conditions are met.

An attacker who can reach the affected interface may call those functions directly. According to the CISA summary, successful abuse can lead to remote code execution, arbitrary file creation or deletion, or disabling of services. Exact request paths, parameters, and preconditions are not detailed here; defenders must obtain those specifics from the F5 advisory rather than relying on third-party descriptions.

Am I affected? How to find it in your systems

F5 BIG-IP appliances and virtual editions commonly sit at network perimeters, in DMZs, or as internal application delivery controllers. Inventory every BIG-IP instance—hardware, VE, and cloud images—including those used only for management or lab purposes.

Telemetry alone cannot prove absence of compromise; pair log review with version inventory and network exposure checks.

How to remediate

Patch first. Apply the updates F5 released for this vulnerability, following the vendor’s installation and reboot guidance. CISA’s required action is exactly that: apply updates per vendor instructions.

If you can't patch immediately

Until the vendor update can be installed, reduce the attack surface and increase detection.

These steps lower risk but do not replace the patch.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently precede broader compromise. If your BIG-IP instances were reachable and unpatched during the period of known exploitation, assume an attacker may have obtained a foothold and investigate accordingly—review logs, check for persistence, and follow your incident-response process. As a simple additional check, you can run a free exposure scan of your email addresses against known breach data to see whether credentials or personal information have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedF5 · BIG-IP
WeaknessCWE-306
Added to CISA KEVMay 10, 2022
Federal patch deadlineMay 31, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities