CVE-2021-22986
Description
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Summary dbcve.org
F5 BIG-IP and BIG-IQ devices contain an unauthenticated remote command execution vulnerability in the iControl REST interface. An attacker can execute arbitrary commands on the underlying system without any authentication, achieving complete system compromise due to the critical CVSS score of 9.8.
Mitigation
Apply the appropriate F5 security patch or upgrade to a fixed version (BIG-IP 16.0.1.1+, 15.1.2.1+, 14.1.4+, 13.1.3.6+, 12.1.5.3+, BIG-IQ 7.1.0.3+, or 7.0.0.2+) immediately. If patching is not immediately feasible, restrict access to the iControl REST interface via network segmentation or firewall rules.