CVE Tools

Description

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

In plain language

AI Act now

A critical security hole in F5 BIG-IP and BIG-IQ lets an attacker send special web requests to run commands on the device without logging in—so if you run these appliances, you should act immediately.

Executive summary

Unauthenticated remote command execution in the iControl REST web management interface of F5 BIG-IP and BIG-IQ appliances (CWE-918) allows an attacker to execute commands as root over the network when the iControl REST interface is exposed.

If affected, business impact
Full takeover of network security deviceService outages and downtimeCustomer/traffic data exposureAttackers can maintain control

What to do now

  1. Check whether your F5 BIG-IP or BIG-IQ appliance is running a vulnerable version and whether the iControl REST interface is exposed/reachable from your network or the internet.
  2. If you’re on an affected version, upgrade to the fixed release: BIG-IP (including access policy manager, advanced firewall manager, advanced web application firewall, analytics, application acceleration manager, application security manager, ddos hybrid defender, domain name system, fraud protection service, global traffic manager, link controller, local traffic manager) fixed in 12.1.5.3.
  3. For BIG-IQ, upgrade per F5 vendor instructions for the iControl REST vulnerability (use the vendor remediation link from this alert to select the correct fixed build for your branch).
  4. After updating, verify the management interface exposure matches your policy (limit access to only trusted networks) and confirm the device no longer accepts the vulnerable behavior.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 14 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Nov 3, 2021
Remediation due:Nov 17, 2021
Ransomware:Known ransomware use

Required action: Apply updates per vendor instructions.

3 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Command and Control
Initial Access
View detailed technique mapping

References

and 5 more references View all →
1

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2021-22986 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store