cbcvebase.
CVE-2021-22989
published 2021-03-31

CVE-2021-22989: On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before…

PriorityP260critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
EPSS
8.84%
94.6th percentile
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, when running in Appliance mode with Advanced WAF or BIG-IP ASM provisioned, the TMUI, also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

Affected

98 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip_aam
f5big-ip_access_policy_manager>= 11.6.1 < 11.6.5.311.6.5.3
f5big-ip_access_policy_manager>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_access_policy_manager>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_access_policy_manager>= 14.1.0 < 14.1.414.1.4
f5big-ip_access_policy_manager>= 15.1.0 < 15.1.2.115.1.2.1
f5big-ip_access_policy_manager>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_advanced_firewall_manager>= 11.6.1 < 11.6.5.311.6.5.3
f5big-ip_advanced_firewall_manager>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_advanced_firewall_manager>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_advanced_firewall_manager>= 14.1.0 < 14.1.414.1.4
f5big-ip_advanced_firewall_manager>= 15.1.0 < 15.1.2.115.1.2.1
f5big-ip_advanced_firewall_manager>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_advanced_waf
f5big-ip_advanced_web_application_firewall>= 11.6.1 < 11.6.5.311.6.5.3
f5big-ip_advanced_web_application_firewall>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_advanced_web_application_firewall>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_advanced_web_application_firewall>= 14.1.0 < 14.1.414.1.4
f5big-ip_advanced_web_application_firewall>= 15.1.0 < 15.1.2.115.1.2.1
f5big-ip_advanced_web_application_firewall>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics>= 11.6.1 < 11.6.5.311.6.5.3
f5big-ip_analytics>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_analytics>= 13.1.0 < 13.1.3.613.1.3.6

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is exploitable only when BIG-IP is running in Appliance mode with Advanced WAF or BIG-IP ASM provisioned — scope detection/hunting to those configurations
  • Attack surface is the TMUI (Configuration utility) — monitor TMUI access logs for authenticated sessions performing unusual or unexpected page requests, especially from non-administrative source IPs
  • Exploitation requires authentication — hunt for brute-force or credential-stuffing activity against TMUI login pages preceding any suspicious RCE indicators
  • ·Vulnerability only manifests when BIG-IP is in Appliance mode AND Advanced WAF or BIG-IP ASM is provisioned; systems not in Appliance mode or without those modules are not affected by this specific CVE
  • ·Affected version ranges span 11.6.x through 16.0.x; fixed versions are 16.0.1.1, 15.1.2.1, 14.1.4, 13.1.3.6, 12.1.5.3, and 11.6.5.3 — ensure asset inventory reflects exact build versions for accurate exposure assessment
  • ·End-of-Software-Development (EoSD) versions were not evaluated by F5 — treat any EoSD BIG-IP running in Appliance mode with ASM/Advanced WAF as potentially vulnerable and prioritise isolation or upgrade
  • ·A broad set of BIG-IP product modules are listed as affected (AAM, AFM, APM, ASM, Advanced WAF, Analytics, DHD, DNS, FPS, GTM, LTM, Link Controller, PEM, SSL Orchestrator) — the common denominator for exploitability remains Appliance mode + ASM/Advanced WAF provisioning

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.