Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🛡️
Not in CISA KEV
HIGH severity

CVE-2022-41622

HIGH

CVE-2022-41622 is a high-severity (CVSS 8.8) Cross-Site Request Forgery (CSRF) vulnerability. EPSS puts its 30-day exploitation probability at 92.4% (100th percentile). No vendor fix is recorded yet; mitigation options are listed below.

In all versions,  BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP.   Note: Software versions which have reached End of Technical…

Published
Updated
Affected
12 products
Patched
See advisory
Exploits
None indexed
Exploitation data as of Oct 7, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • A successful exploit gives an attacker total control of the affected component, not partial access.
  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for CVE-2022-41622.

EPSS Exploitation Probability

via FIRST.org ↗
92.4%probability of exploitation in next 30 days
Very High Risk+0.10%
Lower risk than most CVEs100th percentile — riskier than 100% of all scored CVEsHighest risk
50.0%66.6%83.3%100.0%59.8%92.3%92.4%May 26Sep 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2022-41622 by exploitation likelihood (EPSS) against impact (CVSS). In the shaded patch-first corner (EPSS 50%+, CVSS 7.0+).

Where this sits among everything scored

Of 384,534 CVEs with a current EPSS score, this one falls in the ≥ 90% band (highlighted). Counts from FIRST.org, log-scaled.

Description

In all versions, 

BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP.  

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

12 products · 57 configurations
Application
big-ip access policy managerf5
≥ 16.1.0 && ≤ 16.1.3
1 version
17.0.0
Application
big-ip advanced firewall managerf5
≥ 16.1.0 && ≤ 16.1.3
1 version
17.0.0
Application
big-ip analyticsf5
≥ 16.1.0 && ≤ 16.1.3
1 version
17.0.0
Application
big-ip application acceleration managerf5
≥ 16.1.0 && ≤ 16.1.3
1 version
17.0.0
Application
big-ip application security managerf5
≥ 16.1.0 && ≤ 16.1.3
1 version
17.0.0
Application
big-ip domain name systemf5
≥ 16.1.0 && ≤ 16.1.3
1 version
17.0.0

Detection & mitigation playbook

Vulnerability
  1. Detect

    Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).

  2. Remediation status

    No fixed release is recorded for CVE-2022-41622 yet. Track the upstream advisory, and apply the exposure-reduction steps below in the meantime.

  3. Mitigate without a patch

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

Frequently Asked Questions

In all versions,  BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
O3 Security · Impact-Aware SCA

Is CVE-2022-41622 in your dependencies?

Find it across , including transitive dependencies.

CVE-2022-41622: CSRF (High 8.8)