CVE-2021-22986
F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 17 November 2021). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 99.90% probability · 100th percentile
- CISA KEV
- Listed 3 November 2021 · due 17 November 2021 · used in ransomware campaigns
- Weakness
- CWE-918
- Affected
- f5/big-ip access policy manager · f5/big-ip advanced firewall manager · f5/big-ip advanced web application firewall · f5/big-ip analytics · f5/big-ip application acceleration manager · f5/big-ip application security manager · f5/big-ip ddos hybrid defender · f5/big-ip domain name system · f5/big-ip fraud protection service · f5/big-ip global traffic manager · f5/big-ip link controller · f5/big-ip local traffic manager · f5/big-ip policy enforcement manager · f5/big-iq centralized management · f5/ssl orchestrator
- Source
- f5sirt@f5.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-22986
References
- http://packetstormsecurity.com/files/162059/F5-iControl-Server-Side-Request-Forgery-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/162066/F5-BIG-IP-16.0.x-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://support.f5.com/csp/article/K03009991Vendor Advisory
- http://packetstormsecurity.com/files/162059/F5-iControl-Server-Side-Request-Forgery-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/162066/F5-BIG-IP-16.0.x-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://support.f5.com/csp/article/K03009991Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22986US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.