CVE-2021-22989
published 2021-03-31CVE-2021-22989: On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before…
PriorityP260critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
EPSS
8.84%
94.6th percentile
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, when running in Appliance mode with Advanced WAF or BIG-IP ASM provisioned, the TMUI, also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Affected
98 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | >= 11.6.1 < 11.6.5.3 | 11.6.5.3 |
| f5 | big-ip_access_policy_manager | >= 12.1.0 < 12.1.5.3 | 12.1.5.3 |
| f5 | big-ip_access_policy_manager | >= 13.1.0 < 13.1.3.6 | 13.1.3.6 |
| f5 | big-ip_access_policy_manager | >= 14.1.0 < 14.1.4 | 14.1.4 |
| f5 | big-ip_access_policy_manager | >= 15.1.0 < 15.1.2.1 | 15.1.2.1 |
| f5 | big-ip_access_policy_manager | >= 16.0.0 < 16.0.1.1 | 16.0.1.1 |
| f5 | big-ip_advanced_firewall_manager | >= 11.6.1 < 11.6.5.3 | 11.6.5.3 |
| f5 | big-ip_advanced_firewall_manager | >= 12.1.0 < 12.1.5.3 | 12.1.5.3 |
| f5 | big-ip_advanced_firewall_manager | >= 13.1.0 < 13.1.3.6 | 13.1.3.6 |
| f5 | big-ip_advanced_firewall_manager | >= 14.1.0 < 14.1.4 | 14.1.4 |
| f5 | big-ip_advanced_firewall_manager | >= 15.1.0 < 15.1.2.1 | 15.1.2.1 |
| f5 | big-ip_advanced_firewall_manager | >= 16.0.0 < 16.0.1.1 | 16.0.1.1 |
| f5 | big-ip_advanced_waf | — | — |
| f5 | big-ip_advanced_web_application_firewall | >= 11.6.1 < 11.6.5.3 | 11.6.5.3 |
| f5 | big-ip_advanced_web_application_firewall | >= 12.1.0 < 12.1.5.3 | 12.1.5.3 |
| f5 | big-ip_advanced_web_application_firewall | >= 13.1.0 < 13.1.3.6 | 13.1.3.6 |
| f5 | big-ip_advanced_web_application_firewall | >= 14.1.0 < 14.1.4 | 14.1.4 |
| f5 | big-ip_advanced_web_application_firewall | >= 15.1.0 < 15.1.2.1 | 15.1.2.1 |
| f5 | big-ip_advanced_web_application_firewall | >= 16.0.0 < 16.0.1.1 | 16.0.1.1 |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | >= 11.6.1 < 11.6.5.3 | 11.6.5.3 |
| f5 | big-ip_analytics | >= 12.1.0 < 12.1.5.3 | 12.1.5.3 |
| f5 | big-ip_analytics | >= 13.1.0 < 13.1.3.6 | 13.1.3.6 |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is exploitable only when BIG-IP is running in Appliance mode with Advanced WAF or BIG-IP ASM provisioned — scope detection/hunting to those configurations ↗
- →Attack surface is the TMUI (Configuration utility) — monitor TMUI access logs for authenticated sessions performing unusual or unexpected page requests, especially from non-administrative source IPs ↗
- →Exploitation requires authentication — hunt for brute-force or credential-stuffing activity against TMUI login pages preceding any suspicious RCE indicators ↗
- ·Vulnerability only manifests when BIG-IP is in Appliance mode AND Advanced WAF or BIG-IP ASM is provisioned; systems not in Appliance mode or without those modules are not affected by this specific CVE ↗
- ·Affected version ranges span 11.6.x through 16.0.x; fixed versions are 16.0.1.1, 15.1.2.1, 14.1.4, 13.1.3.6, 12.1.5.3, and 11.6.5.3 — ensure asset inventory reflects exact build versions for accurate exposure assessment ↗
- ·End-of-Software-Development (EoSD) versions were not evaluated by F5 — treat any EoSD BIG-IP running in Appliance mode with ASM/Advanced WAF as potentially vulnerable and prioritise isolation or upgrade ↗
- ·A broad set of BIG-IP product modules are listed as affected (AAM, AFM, APM, ASM, Advanced WAF, Analytics, DHD, DNS, FPS, GTM, LTM, Link Controller, PEM, SSL Orchestrator) — the common denominator for exploitability remains Appliance mode + ASM/Advanced WAF provisioning ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2021-22989: On BIG-IP versions 16
vendor_f5·2021-03-31·CVSS 9.1
CVE-2021-22989 [CRITICAL] CVE-2021-22989: On BIG-IP versions 16
CVE-2021-22989: On BIG-IP versions 16
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, when running in Appliance mode with Advanced WAF or BIG-IP ASM provisioned, the TMUI, also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Advanced WAF, BIG-IP Analytics, BIG-IP DHD, BIG-IP DNS, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, Ssl Orchestrator
Affected Versions: 11.6.1 - 11.6.5.3; 12.1.0 - 12.1.5.3; 13.1.0
GHSA
GHSA-86gp-vc79-86x4: On BIG-IP versions 16
ghsa_unreviewed·2022-05-24
CVE-2021-22989 [CRITICAL] GHSA-86gp-vc79-86x4: On BIG-IP versions 16
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, when running in Appliance mode with Advanced WAF or BIG-IP ASM provisioned, the TMUI, also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
No detection rules found.
No public exploits indexed.
Fortinet
Defending Against Critical F5 Vulnerabilities | FortiGuard Labs
blogs_fortinet·2021-03-23·CVSS 9.8
[CRITICAL] Defending Against Critical F5 Vulnerabilities | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Defending Against Critical F5 Vulnerabilities
By FortiGuard Labs | March 23, 2021
FortiGuard Labs Threat Update
FortiGuard Labs has been actively monitoring efforts by attackers around the world to scan for and locate devices vulnerable to recently revealed flaws in the F5 BIG-IP/BIG-IQ family of application availability, access control, and security solutions. In addition, we have identified multiple instances of new proof of concept code being posted to known sites that could be used to exploit these vulnerabilities, further demonstrating the need to apply patches quickly.
F5 BIG-IP is an application delivery controller (ADC) used for load balancing and facilitating the movement of web traffic to its destination, and BIG-IQ provides centralized manage
Tenable
CVE-2021-22986: F5 Patches Several Critical Vulnerabilities in BIG-IP, BIG-IQ
blogs_tenable·2021-03-11·CVSS 9.8
[CRITICAL] CVE-2021-22986: F5 Patches Several Critical Vulnerabilities in BIG-IP, BIG-IQ
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
2021-03-31
Published