CVE-2021-22986: F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Other sources
F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
F5 BIG-IPto a version that resolves this vulnerability.Fixed in 16.0.1.1 - Upgrade
Upgrade
F5 BIG-IPto a version that resolves this vulnerability.Fixed in 15.1.2.1 - Upgrade
Upgrade
F5 BIG-IPto a version that resolves this vulnerability.Fixed in 14.1.4 - Upgrade
Upgrade
F5 BIG-IPto a version that resolves this vulnerability.Fixed in 13.1.3.6 - Upgrade
Upgrade
F5 BIG-IPto a version that resolves this vulnerability.Fixed in 12.1.5.3 - Upgrade
Upgrade
F5 BIG-IQ Centralized Managementto a version that resolves this vulnerability.Fixed in 7.1.0.3 - Upgrade
Upgrade
F5 BIG-IQ Centralized Managementto a version that resolves this vulnerability.Fixed in 7.0.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22986?
CVE-2021-22986 is considered critical due to its potential to allow unauthenticated remote command execution.
How do I fix CVE-2021-22986?
To fix CVE-2021-22986, upgrade to the latest patched version of BIG-IP or BIG-IQ as specified in the F5 security advisories.
Which versions are affected by CVE-2021-22986?
CVE-2021-22986 affects several versions of F5 BIG-IP and BIG-IQ, including versions below 16.0.1.1 for BIG-IP and below 7.1.0.3 for BIG-IQ.
What products are impacted by CVE-2021-22986?
CVE-2021-22986 impacts F5 products including BIG-IP, BIG-IQ, Advanced Firewall Manager, and Application Security Manager.
Is CVE-2021-22986 being actively exploited?
At the time of the advisory, there are no confirmed reports of active exploitation of CVE-2021-22986, but immediate mitigation is recommended.