cbcvebase.
CVE-2021-22986
published 2021-03-31

CVE-2021-22986: On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x…

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
99.90%
100.0th percentile
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

Affected

89 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip_aam
f5big-ip_access_policy_manager>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_access_policy_manager>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_access_policy_manager>= 14.1.0 < 14.1.414.1.4
f5big-ip_access_policy_manager>= 15.1.0 < 15.1.2.115.1.2.1
f5big-ip_access_policy_manager>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_advanced_firewall_manager>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_advanced_firewall_manager>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_advanced_firewall_manager>= 14.1.0 < 14.1.414.1.4
f5big-ip_advanced_firewall_manager>= 15.1.0 < 15.1.2.115.1.2.1
f5big-ip_advanced_firewall_manager>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_advanced_waf
f5big-ip_advanced_web_application_firewall>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_advanced_web_application_firewall>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_advanced_web_application_firewall>= 14.1.0 < 14.1.414.1.4
f5big-ip_advanced_web_application_firewall>= 15.1.0 < 15.1.2.115.1.2.1
f5big-ip_advanced_web_application_firewall>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_analytics>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_analytics>= 14.1.0 < 14.1.414.1.4
f5big-ip_analytics>= 15.1.0 < 15.1.2.115.1.2.1
f5big-ip_analytics>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_apm

Detection & IOCsextracted from sources · hover to see the quote

url/mgmt/shared/authn/login
otherX-F5-Auth-Token
  • Monitor for unauthenticated POST requests to /mgmt/shared/authn/login that are followed by use of an X-F5-Auth-Token to reach privileged iControl REST endpoints — this is the SSRF token-generation chain for CVE-2021-22986.
  • Alert on any unauthenticated access attempts to the iControl REST interface from untrusted networks; CVE-2021-22986 is an unauthenticated remote command execution vulnerability in that interface.
  • CVE-2021-22986 was actively exploited shortly after patch release with multiple public PoCs; treat any spike in iControl REST traffic as a high-priority indicator of exploitation attempts.
  • ·Affected BIG-IP versions for CVE-2021-22986 span multiple branches; ensure detection/patching coverage includes all listed ranges.
  • ·BIG-IQ is also in scope for CVE-2021-22986, not just BIG-IP; ensure BIG-IQ 7.0.0.x and 7.1.0.x deployments are included in detection and patching scope.
  • ·CVE-2021-22986 has been leveraged by the LockBit ransomware group in real-world attacks (e.g., the Accenture breach); treat exploitation of this CVE as a potential ransomware precursor.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.