F5 BIG-IP administrators are being warned to immediately install the latest security updates, as a critical remote code execution flaw CVE-2022-1388.
See also: Google: Fixes exploitable vulnerability in Android kernel

Last week, F5 disclosed a new critical vulnerability in BIG-IP networking devices tracked as CVE-2022-1388. This vulnerability affects the BIG-IP iControl REST authentication component and allows remote threat actors to bypass authentication and execute commands on the device with elevated privileges.
As F5 BIG-IP devices are commonly used in the enterprise, this vulnerability is a significant risk as it would allow threat actors to exploit the flaw to gain initial access to networks and then spread laterally to other devices. These types of attacks could be used to steal corporate data or deploy ransomware across all devices on the network.
Cybersecurity researchers from Horizon3 and Positive Technologies were able to create exploits for the new F5 BIG-IP vulnerability. They warned that all administrators should immediately update devices as soon as possible due to the dangerous nature of the exploit.
See also: Leak of Greek student data: Vulnerability in UniverSIS!

Zach Hanley, Chief Attack Engineer at Horizon3, said it only took them two days to discover the exploit and they expect threat actors to start exploiting devices soon.
Hanley also warned that the impact of this exploit will be significant, as it allows threat actors to gain root to devices, which they will use for initial access to corporate networks.
However, Rapid7 researcher Jacob Bainestweeted that there are still 2,500 devices exposed to the internet.
Horizon3 says it will publicly release its proof-of-concept exploit this week to encourage organizations to patch devices .
See also: Google fixed a strange bug that crashed the Docs app

The good news is that F5 has already released security updates that administrators can apply for the following firmware versions:
BIG-IP versions 16.1.0 to 16.1.2 (patch released)
BIG-IP versions 15.1.0 through 15.1.5 (patch released)
BIG-IP versions 14.1.0 through 14.1.4 (patch released)
BIG-IP versions 13.1.0 through 13.1.4 (patch released)
BIG-IP versions 12.1.0 through 12.1.6 (End of support)
BIG-IP versions 11.6.1 through 11.6.5 (End of support)
Those running firmware versions 11.x and 12.x will not receive security updates and should upgrade to a newer version as soon as possible.
