Umbra Wiki cve cve/CVE-2021-22986
Back to wiki

CVE-2021-22986 — F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

provenance: imported · CVE: CVE-2021-22986

CVE-2021-22986: F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project F5
Product BIG-IP and BIG-IQ Centralized Management
Date added 2021-11-03
Due date 2021-11-17
Ransomware campaign use Known

Description

F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2021-22986

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2021-22986
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog