cbcvebase.
CVE-2021-22987
published 2021-03-31

CVE-2021-22987: On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before…

PriorityP274critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
13.67%
96.1th percentile
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3 when running in Appliance mode, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

Affected

98 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip_aam
f5big-ip_access_policy_manager>= 11.6.1 < 11.6.5.311.6.5.3
f5big-ip_access_policy_manager>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_access_policy_manager>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_access_policy_manager>= 14.1.0 < 14.1.414.1.4
f5big-ip_access_policy_manager>= 15.1.0 < 15.1.2.115.1.2.1
f5big-ip_access_policy_manager>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_advanced_firewall_manager>= 11.6.1 < 11.6.5.311.6.5.3
f5big-ip_advanced_firewall_manager>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_advanced_firewall_manager>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_advanced_firewall_manager>= 14.1.0 < 14.1.414.1.4
f5big-ip_advanced_firewall_manager>= 15.1.0 < 15.1.2.115.1.2.1
f5big-ip_advanced_firewall_manager>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_advanced_waf
f5big-ip_advanced_web_application_firewall>= 11.6.1 < 11.6.5.311.6.5.3
f5big-ip_advanced_web_application_firewall>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_advanced_web_application_firewall>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_advanced_web_application_firewall>= 14.1.0 < 14.1.414.1.4
f5big-ip_advanced_web_application_firewall>= 15.1.0 < 15.1.2.115.1.2.1
f5big-ip_advanced_web_application_firewall>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics>= 11.6.1 < 11.6.5.311.6.5.3
f5big-ip_analytics>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_analytics>= 13.1.0 < 13.1.3.613.1.3.6

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is exploitable only when BIG-IP is running in Appliance mode; confirm Appliance mode is active before triaging exploitation attempts
  • Target attack surface is the TMUI (Configuration utility) — monitor HTTP/S access logs to TMUI/Configuration utility pages for anomalous authenticated sessions performing unexpected actions
  • Exploitation requires authentication; look for authenticated sessions followed by unusual command execution or process spawning from the TMUI process
  • ·Vulnerability only affects BIG-IP instances running in Appliance mode; non-Appliance mode deployments are not affected by this specific CVE
  • ·Affected version ranges span six major branches: 11.6.x before 11.6.5.3, 12.1.x before 12.1.5.3, 13.1.x before 13.1.3.6, 14.1.x before 14.1.4, 15.1.x before 15.1.2.1, and 16.0.x before 16.0.1.1
  • ·End-of-Software-Development (EoSD) versions were not evaluated; those branches may also be vulnerable but are unsupported
  • ·Affected product lines include BIG-IP AAM, AFM, APM, ASM, Advanced WAF, Analytics, DHD, DNS, FPS, GTM, LTM, Link Controller, PEM, and SSL Orchestrator

CVSS provenance

nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.