CVE-2021-22986
Description
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
In plain language
AI Act nowA critical security hole in F5 BIG-IP and BIG-IQ lets an attacker send special web requests to run commands on the device without logging in—so if you run these appliances, you should act immediately.
Unauthenticated remote command execution in the iControl REST web management interface of F5 BIG-IP and BIG-IQ appliances (CWE-918) allows an attacker to execute commands as root over the network when the iControl REST interface is exposed.
What to do now
- Check whether your F5 BIG-IP or BIG-IQ appliance is running a vulnerable version and whether the iControl REST interface is exposed/reachable from your network or the internet.
- If you’re on an affected version, upgrade to the fixed release: BIG-IP (including access policy manager, advanced firewall manager, advanced web application firewall, analytics, application acceleration manager, application security manager, ddos hybrid defender, domain name system, fraud protection service, global traffic manager, link controller, local traffic manager) fixed in 12.1.5.3.
- For BIG-IQ, upgrade per F5 vendor instructions for the iControl REST vulnerability (use the vendor remediation link from this alert to select the correct fixed build for your branch).
- After updating, verify the management interface exposure matches your policy (limit access to only trusted networks) and confirm the device no longer accepts the vulnerable behavior.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2021-22986 and every CVE in our database. Create a free account — no credit card required.
Create Free Account