AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .9995 100.0 YES
AFFECTED Product Versions Fixed BIG-IP 16.1.x – 17.0.0
TIMELINE Apr 19 Reserved by f5 May 5 Published (CNA: f5) May 10 Added to CISA KEV, remediation due 2022-05-31
Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .9995 100.0 YES
AFFECTED Product Versions Fixed BIG-IP 16.1.x – 17.0.0
TIMELINE Apr 19 Reserved by f5 May 5 Published (CNA: f5) May 10 Added to CISA KEV, remediation due 2022-05-31
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
| Date | Event | Detail |
|---|---|---|
| April 19, 2022 | Reserved | Reserved by f5 |
| May 5, 2022 | Published | Published (CNA: f5) |
| May 10, 2022 | KEV ADDED | Added to CISA KEV, remediation due 2022-05-31 |
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
|---|---|---|---|---|
| F5 | BIG-IP | — | 16.1.x | 17.0.0 |
Authoritative record: CVE-2022-1388 at cve.org
Vendors: f5
Weaknesses: CWE-306
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2022-1388 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.