F5 BIG-IP是美国F5公司的一款集成了网络流量管理、应用程序安全管理、负载均衡等功能的应用交付平台。 F5 BIG-IP 存在访问控制错误漏洞,攻击者可以通过未公开的请求利用该漏洞绕过BIG-IP中的iControl REST身份验证来控制受影响的系统。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | K23605346: BIG-IP iControl REST vulnerability CVE-2022-1388 | https://github.com/numanturle/CVE-2022-1388 | POC Details |
| 2 | Simple script realizado en bash, para revisión de múltiples hosts para CVE-2022-1388 (F5) | https://github.com/jheeree/CVE-2022-1388-checker | POC Details |
| 3 | This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only. | https://github.com/MrCl0wnLab/Nuclei-Template-CVE-2022-1388-BIG-IP-iControl-REST-Exposed | POC Details |
| 4 | A vulnerability scanner that detects CVE-2021-21980 vulnerabilities. | https://github.com/Osyanina/westone-CVE-2022-1388-scanner | POC Details |
| 5 | CVE-2022-1388 F5 BIG-IP RCE 批量检测 | https://github.com/doocop/CVE-2022-1388-EXP | POC Details |
| 6 | None | https://github.com/blind-intruder/CVE-2022-1388-RCE-checker-and-POC-Exploit | POC Details |
| 7 | None | https://github.com/Hudi233/CVE-2022-1388 | POC Details |
| 8 | PoC for CVE-2022-1388_F5_BIG-IP | https://github.com/sherlocksecurity/CVE-2022-1388-Exploit-POC | POC Details |
| 9 | batch scan CVE-2022-1388 | https://github.com/yukar1z0e/CVE-2022-1388 | POC Details |
| 10 | CVE-2022-1388 F5 BIG-IP iControl REST Auth Bypass RCE | https://github.com/0xf4n9x/CVE-2022-1388 | POC Details |
| 11 | F5 BIG-IP RCE exploitation (CVE-2022-1388) | https://github.com/alt3kx/CVE-2022-1388_PoC | POC Details |
| 12 | CVE-2022-1388 F5 Big IP unauth remote code execution | https://github.com/Vulnmachines/F5-Big-IP-CVE-2022-1388 | POC Details |
| 13 | Exploit and Check Script for CVE 2022-1388 | https://github.com/ZephrFish/F5-CVE-2022-1388-Exploit | POC Details |
| 14 | POC for CVE-2022-1388 | https://github.com/horizon3ai/CVE-2022-1388 | POC Details |
| 15 | CVE-2022-1388 F5 BIG-IP iControl REST RCE | https://github.com/Al1ex/CVE-2022-1388 | POC Details |
| 16 | F5 BIG-IP iControl REST身份验证绕过漏洞 | https://github.com/Henry4E36/CVE-2022-1388 | POC Details |
| 17 | CVE-2022-1388 F5 BIG-IP iControl REST身份验证绕过漏洞 | https://github.com/savior-only/CVE-2022-1388 | POC Details |
| 18 | CVE-2022-1388 | https://github.com/saucer-man/CVE-2022-1388 | POC Details |
| 19 | CVE-2022-1388 POC exploit | https://github.com/superzerosec/CVE-2022-1388 | POC Details |
| 20 | PoC For F5 BIG-IP - bash script Exploit one Liner | https://github.com/Stonzyy/Exploit-F5-CVE-2022-1388 | POC Details |
| 21 | CVE-2022-1388 is an authentication bypass vulnerability in the REST component of BIG-IP’s iControl API that was assigned a CVSSv3 score of 9.8. The iControl REST API is used for the management and configuration of BIG-IP devices. CVE-2022-1388 could be exploited by an unauthenticated attacker with network access to the management port or self IP addresses of devices that use BIG-IP. Exploitation would allow the attacker to execute arbitrary system commands, create and delete files and disable services. | https://github.com/MrCl0wnLab/Nuclei-Template-Exploit-F5-BIG-IP-iControl-REST-Auth-Bypass-RCE-Command-Parameter | POC Details |
| 22 | Reverse Shell for CVE-2022-1388 | https://github.com/qusaialhaddad/F5-BigIP-CVE-2022-1388 | POC Details |
| 23 | POC of CVE-2022-1388 | https://github.com/chesterblue/CVE-2022-1388 | POC Details |
| 24 | None | https://github.com/Angus-Team/F5-BIG-IP-RCE-CVE-2022-1388 | POC Details |
| 25 | CVE-2022-1388-EXP可批量实现攻击 | https://github.com/LinJacck/CVE-2022-1388-EXP | POC Details |
| 26 | Simple shell script for the exploit | https://github.com/iveresk/cve-2022-1388-1veresk | POC Details |
| 27 | BIG-IP iControl REST vulnerability CVE-2022-1388 PoC | https://github.com/shamo0/CVE-2022-1388 | POC Details |
| 28 | None | https://github.com/vesperp/CVE-2022-1388-F5-BIG-IP | POC Details |
| 29 | Test and Exploit Scripts for CVE 2022-1388 (F5 Big-IP) | https://github.com/thatonesecguy/CVE-2022-1388-Exploit | POC Details |
| 30 | A Test API for testing the POC against CVE-2022-1388 | https://github.com/bandit92/CVE2022-1388_TestAPI | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-25946 | 8.7 HIGH | F5 BIG-IP 安全漏洞 |
| CVE-2022-27806 | 8.7 HIGH | F5 BIG-IP多款产品命令注入漏洞 |
| CVE-2022-28707 | 8.0 HIGH | F5 BIG-IP 跨站脚本漏洞 |
| CVE-2022-29263 | 7.8 HIGH | F5 BIG-IP APM 安全漏洞 |
| CVE-2022-26415 | 7.7 HIGH | F5 BIG-IP 命令注入漏洞 |
| CVE-2022-29491 | 7.5 HIGH | F5 BIG-IP多款产品代码问题漏洞 |
| CVE-2022-27189 | 7.5 HIGH | F5 BIG-IP 安全漏洞 |
| CVE-2022-27230 | 7.5 HIGH | F5 BIG-IP APM 跨站脚本漏洞 |
| CVE-2022-26372 | 7.5 HIGH | F5 BIG-IP 资源管理错误漏洞 |
| CVE-2022-28691 | 7.5 HIGH | F5 BIG-IP 资源管理错误漏洞 |
| CVE-2022-28701 | 7.5 HIGH | F5 BIG-IP 资源管理错误漏洞 |
| CVE-2022-28705 | 7.5 HIGH | F5 BIG-IP 输入验证错误漏洞 |
| CVE-2022-28716 | 7.5 HIGH | F5 BIG-IP 跨站脚本漏洞 |
| CVE-2022-26890 | 7.5 HIGH | 多款F5 BIG-IP产品安全漏洞 |
| CVE-2022-26071 | 7.4 HIGH | F5 BIG-IP 安全特征问题漏洞 |
| CVE-2022-28714 | 7.3 HIGH | F5 BIG-IP 代码问题漏洞 |
| CVE-2022-28695 | 7.2 HIGH | F5 BIG-IP AFM 代码问题漏洞 |
| CVE-2022-27878 | 6.8 MEDIUM | F5 BIG-IP 多款产品跨站脚本漏洞 |
| CVE-2022-28859 | 6.5 MEDIUM | F5 BIG-IP 日志信息泄露漏洞 |
| CVE-2022-27495 | 6.5 MEDIUM | F5 NGINX Service Mesh 访问控制错误漏洞 |
Showing top 20 of 43 CVEs. View all on vendor page → →
No comments yet