Threat Intelligence Report regarding BIG-IP F5 Firewall vulnerability (CVE-2022-1388)

On May 9, 2022, additional information was published about a vulnerability in the iControl REST API of F5’s BIG-IP firewall products that could allow attackers to gain full access to the firewall and underlying network components. The specific vulnerability for which this Threat Intelligence Report was written concerns CVE-2022-1388 and allows an attacker, without authenticating, to execute top-level (root) code on the affected system. Given the severity of these vulnerabilities, NFIR recommends that the patches made available be installed as soon as possible.

The Threat Intelligence Report provides details of these vulnerabilities and what steps your organization can take.

SECURITY INCIDENT AT YOUR ORGANIZATION?

The next 30 minutes are crucial!

The first 30 minutes after a cyber security incident are crucial because a quick and adequate response can limit the damage. In addition, further spread of the attack can be prevented and essential evidence can be secured for further investigation.

Our Computer Emergency Response Team (CERT) is available 24/7 to support businesses and organizations during IT security incidents.

SECURITY INCIDENT AT YOUR ORGANIZATION?

The next 30 minutes are crucial!

The first 30 minutes after a cyber security incident are crucial because a quick and adequate response can limit the damage. In addition, further spread of the attack can be prevented and essential evidence can be secured for further investigation.

Our Computer Emergency Response Team (CERT) is available 24/7 to support businesses and organizations during IT security incidents.

SECURITY INCIDENT AT YOUR ORGANIZATION?

The next 30 minutes are crucial!

The first 30 minutes after a cyber security incident are crucial because a quick and adequate response can limit the damage. In addition, further spread of the attack can be prevented and essential evidence can be secured for further investigation.

Our Computer Emergency Response Team (CERT) is available 24/7 to support businesses and organizations during IT security incidents.