Skip to content
← LibraryTechnique entry
CVE-F5-BIGIPInitial Access

F5 BIG-IP iControl REST Auth Bypass (CVE-2022-1388)

Connection-header SMUGGLE to bypass iControl REST auth → command-injection → root on the load balancer.

§ Where this technique fits

CVE-F5-BIGIP is catalogued under the Initial Access tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 2 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01seen 1×