CRITICAL

CVE-2021-22986

F5 Big Ip Access Policy Manager 2021-03-31 CVSS v3.1
CVSS
9.8
KEV

Description

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

Summary dbcve.org

F5 BIG-IP and BIG-IQ devices contain an unauthenticated remote command execution vulnerability in the iControl REST interface. An attacker can execute arbitrary commands on the underlying system without any authentication, achieving complete system compromise due to the critical CVSS score of 9.8.

Mitigation

Apply the appropriate F5 security patch or upgrade to a fixed version (BIG-IP 16.0.1.1+, 15.1.2.1+, 14.1.4+, 13.1.3.6+, 12.1.5.3+, BIG-IQ 7.1.0.3+, or 7.0.0.2+) immediately. If patching is not immediately feasible, restrict access to the iControl REST interface via network segmentation or firewall rules.

Proof of Concept

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

99.9%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE