CVE-2021-22987
published 2021-03-31CVE-2021-22987: On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before…
PriorityP274critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
13.67%
96.1th percentile
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3 when running in Appliance mode, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Affected
98 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | >= 11.6.1 < 11.6.5.3 | 11.6.5.3 |
| f5 | big-ip_access_policy_manager | >= 12.1.0 < 12.1.5.3 | 12.1.5.3 |
| f5 | big-ip_access_policy_manager | >= 13.1.0 < 13.1.3.6 | 13.1.3.6 |
| f5 | big-ip_access_policy_manager | >= 14.1.0 < 14.1.4 | 14.1.4 |
| f5 | big-ip_access_policy_manager | >= 15.1.0 < 15.1.2.1 | 15.1.2.1 |
| f5 | big-ip_access_policy_manager | >= 16.0.0 < 16.0.1.1 | 16.0.1.1 |
| f5 | big-ip_advanced_firewall_manager | >= 11.6.1 < 11.6.5.3 | 11.6.5.3 |
| f5 | big-ip_advanced_firewall_manager | >= 12.1.0 < 12.1.5.3 | 12.1.5.3 |
| f5 | big-ip_advanced_firewall_manager | >= 13.1.0 < 13.1.3.6 | 13.1.3.6 |
| f5 | big-ip_advanced_firewall_manager | >= 14.1.0 < 14.1.4 | 14.1.4 |
| f5 | big-ip_advanced_firewall_manager | >= 15.1.0 < 15.1.2.1 | 15.1.2.1 |
| f5 | big-ip_advanced_firewall_manager | >= 16.0.0 < 16.0.1.1 | 16.0.1.1 |
| f5 | big-ip_advanced_waf | — | — |
| f5 | big-ip_advanced_web_application_firewall | >= 11.6.1 < 11.6.5.3 | 11.6.5.3 |
| f5 | big-ip_advanced_web_application_firewall | >= 12.1.0 < 12.1.5.3 | 12.1.5.3 |
| f5 | big-ip_advanced_web_application_firewall | >= 13.1.0 < 13.1.3.6 | 13.1.3.6 |
| f5 | big-ip_advanced_web_application_firewall | >= 14.1.0 < 14.1.4 | 14.1.4 |
| f5 | big-ip_advanced_web_application_firewall | >= 15.1.0 < 15.1.2.1 | 15.1.2.1 |
| f5 | big-ip_advanced_web_application_firewall | >= 16.0.0 < 16.0.1.1 | 16.0.1.1 |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | >= 11.6.1 < 11.6.5.3 | 11.6.5.3 |
| f5 | big-ip_analytics | >= 12.1.0 < 12.1.5.3 | 12.1.5.3 |
| f5 | big-ip_analytics | >= 13.1.0 < 13.1.3.6 | 13.1.3.6 |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is exploitable only when BIG-IP is running in Appliance mode; confirm Appliance mode is active before triaging exploitation attempts ↗
- →Target attack surface is the TMUI (Configuration utility) — monitor HTTP/S access logs to TMUI/Configuration utility pages for anomalous authenticated sessions performing unexpected actions ↗
- →Exploitation requires authentication; look for authenticated sessions followed by unusual command execution or process spawning from the TMUI process ↗
- ·Vulnerability only affects BIG-IP instances running in Appliance mode; non-Appliance mode deployments are not affected by this specific CVE ↗
- ·Affected version ranges span six major branches: 11.6.x before 11.6.5.3, 12.1.x before 12.1.5.3, 13.1.x before 13.1.3.6, 14.1.x before 14.1.4, 15.1.x before 15.1.2.1, and 16.0.x before 16.0.1.1 ↗
- ·End-of-Software-Development (EoSD) versions were not evaluated; those branches may also be vulnerable but are unsupported ↗
- ·Affected product lines include BIG-IP AAM, AFM, APM, ASM, Advanced WAF, Analytics, DHD, DNS, FPS, GTM, LTM, Link Controller, PEM, and SSL Orchestrator ↗
CVSS provenance
nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h6q8-h24w-7xp3: On BIG-IP versions 16
ghsa_unreviewed·2022-05-24
CVE-2021-22987 [CRITICAL] GHSA-h6q8-h24w-7xp3: On BIG-IP versions 16
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3 when running in Appliance mode, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
F5
CVE-2021-22987: On BIG-IP versions 16
vendor_f5·2021-03-31·CVSS 9.9
CVE-2021-22987 [CRITICAL] CVE-2021-22987: On BIG-IP versions 16
CVE-2021-22987: On BIG-IP versions 16
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3 when running in Appliance mode, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Advanced WAF, BIG-IP Analytics, BIG-IP DHD, BIG-IP DNS, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, Ssl Orchestrator
Affected Versions: 11.6.1 - 11.6.5.3; 12.1.0 - 12.1.5.3; 13.1.0 - 13.1.3.
No detection rules found.
No public exploits indexed.
Fortinet
Defending Against Critical F5 Vulnerabilities | FortiGuard Labs
blogs_fortinet·2021-03-23·CVSS 9.8
[CRITICAL] Defending Against Critical F5 Vulnerabilities | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Defending Against Critical F5 Vulnerabilities
By FortiGuard Labs | March 23, 2021
FortiGuard Labs Threat Update
FortiGuard Labs has been actively monitoring efforts by attackers around the world to scan for and locate devices vulnerable to recently revealed flaws in the F5 BIG-IP/BIG-IQ family of application availability, access control, and security solutions. In addition, we have identified multiple instances of new proof of concept code being posted to known sites that could be used to exploit these vulnerabilities, further demonstrating the need to apply patches quickly.
F5 BIG-IP is an application delivery controller (ADC) used for load balancing and facilitating the movement of web traffic to its destination, and BIG-IQ provides centralized manage
Tenable
CVE-2021-22986: F5 Patches Several Critical Vulnerabilities in BIG-IP, BIG-IQ
blogs_tenable·2021-03-11·CVSS 9.8
[CRITICAL] CVE-2021-22986: F5 Patches Several Critical Vulnerabilities in BIG-IP, BIG-IQ
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
2021-03-31
Published