Database/Control plane, storage & DevOps
F5 BIG-IP (iControl REST): An unauthenticated attacker can send undisclosed requests to the iControl REST management
Impact
An unauthenticated attacker can send undisclosed requests to the iControl REST management API and bypass authentication entirely, then run arbitrary system commands, create/delete files, or disable services — full compromise of the load balancer. This is one of the most widely exploited F5 bugs on record and is confirmed in CISA's KEV catalog; mass scanning for it started within days of disclosure.
Who can reach it
Remote and unauthenticated, but only if the iControl REST management interface is reachable from the attacker's network position — the standard defense-in-depth advice from F5 is that this interface should never be internet-facing, only reachable from a management network.
What to do
Software upgrade to the fixed BIG-IP version per F5 K23605346, then reboot; if immediate patching isn't possible, restricting iControl REST access to a trusted management network (or disabling it on the self-IP/external interfaces) is the documented interim mitigation. Given confirmed mass exploitation, treat any unpatched device with an internet-reachable management plane as likely already compromised, not just vulnerable.
References
Related entries
- Cisco Nexus Dashboard (web UI / CSRF): One of a batch of unauthenticated flaws in Nexus Dashboard that together allowCVE-2022-20861 · Cisco Nexus Dashboard (web UI / CSRF)Critical
- Citrix ADC/Gateway: SAML SP/IdP configCVE-2022-27518 · Citrix ADC/GatewayCritical
- Brocade SANnav Management Portal - Zone management endpoints, before SANnav 2.2.0: SQL injection in multiple endpointsCVE-2022-28163 · Brocade SANnav Management Portal - Zone management endpoints, before SANnav 2.2.0Critical
- Pure Storage Purity//FA and Purity//FB management interface (exposed credential): A password for the array's managementCVE-2022-32554 · Pure Storage Purity//FA and Purity//FB management interface (exposed credential)Critical
- Brocade Fabric OS (unauthenticated remote code execution): Unauthenticated remote code execution on a Fibre ChannelCVE-2022-33186 · Brocade Fabric OS (unauthenticated remote code execution)Critical
- Fortinet FortiOS/FortiProxy: Auth bypass via an alternate pathCVE-2022-40684 · Fortinet FortiOS/FortiProxyCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.