On Wednesday, Cloud security and ADN provider F5 released patches that contained 43 bugs affecting the company’s many products. Among these bugs, there is a critical one that could lead an unauthenticated attacker to perform the following actions:-
The 43 issues addressed are rated as follows:-
The critical one has been assigned to CVE-2022-1388, and it has a CVSS v3 severity ranking of 9.8. This flaw arises as a result of an insufficient authentication check, and it could possibly be exploited by malicious actors to take control of a compromised system.
It is a serious flaw in the iControl REST component. It would allow a malicious actor to send undeclared requests in order to bypass the iControl REST authentication in BIG-IP and circumvent the control.
Here below we have mentioned all the affected products:-
While a fix has been introduced to F5’s customers in versions 17.0.0, 16.1.2.2, 15.1.5.1, 14.1.4.6, and 13.1.5. However, patching will not be applied to the 12.x and 11.x branches.
Apart from this, the advisory clarifies that the following things are not impacted by CVE-2022-1388:-
Moreover, the CISA has published a list of five new vulnerabilities that are based on proof of active exploitation, and here we have listed the flaws below:-
This vulnerability could potentially be exploited in the enterprise by threat actors to gain access to corporate networks using F5 BIG-IP devices.
It appears that Shodan currently shows that 16,142 F5 BIG-IP devices are publicly exposed to the internet, using the query shared by Warfield in the query aforementioned.
Because of this, the network administrators have been advised to patch these devices immediately. Not only that even there has already been considerable effort put into narrowing down the location of the vulnerability by the security researchers.
As a temporary workaround, F5 has offered some workarounds for the time being, and here they are:-
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…