cbcvebase.
CVE-2021-23025
published 2021-09-14

CVE-2021-23025: On version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all versions of 12.1.x and 11.6.x, an authenticated remote command…

PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.29%
81.3th percentile
On version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all versions of 12.1.x and 11.6.x, an authenticated remote command execution vulnerability exists in the BIG-IP Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected

85 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip_aam
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager11.6.1 – 11.6.5
f5big-ip_access_policy_manager12.1.0 – 12.1.6
f5big-ip_access_policy_manager>= 13.1.0 < 13.1.3.513.1.3.5
f5big-ip_access_policy_manager>= 14.1.0 < 14.1.3.114.1.3.1
f5big-ip_access_policy_manager>= 15.0.0 < 15.1.0.515.1.0.5
f5big-ip_advanced_firewall_manager11.6.1 – 11.6.5
f5big-ip_advanced_firewall_manager12.1.0 – 12.1.6
f5big-ip_advanced_firewall_manager>= 13.1.0 < 13.1.3.513.1.3.5
f5big-ip_advanced_firewall_manager>= 14.1.0 < 14.1.3.114.1.3.1
f5big-ip_advanced_firewall_manager>= 15.0.0 < 15.1.0.515.1.0.5
f5big-ip_advanced_waf
f5big-ip_advanced_web_application_firewall11.6.1 – 11.6.5
f5big-ip_advanced_web_application_firewall12.1.0 – 12.1.6
f5big-ip_advanced_web_application_firewall>= 13.1.0 < 13.1.3.513.1.3.5
f5big-ip_advanced_web_application_firewall>= 14.1.0 < 14.1.3.114.1.3.1
f5big-ip_advanced_web_application_firewall>= 15.0.0 < 15.1.0.515.1.0.5
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics11.6.1 – 11.6.5
f5big-ip_analytics12.1.0 – 12.1.6
f5big-ip_analytics>= 13.1.0 < 13.1.3.513.1.3.5
f5big-ip_analytics>= 14.1.0 < 14.1.3.114.1.3.1
f5big-ip_analytics>= 15.0.0 < 15.1.0.515.1.0.5

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability exists in the BIG-IP Configuration utility (TMUI); monitor for authenticated remote command execution attempts originating from the management interface or self-IP access to the Configuration utility.
  • Affected BIG-IP versions to flag in asset inventory and patch prioritization: 11.6.1–11.6.5, 12.1.0–12.1.6, 13.1.0–13.1.3.5, 14.1.0–14.1.3.1, 15.0.0–15.1.0.5.
  • ·Exploitation requires authentication; attack surface is limited to users with valid credentials to the BIG-IP Configuration utility. Restrict management access to trusted networks/IPs to reduce exposure.
  • ·End-of-Technical-Support (EoTS) versions (11.6.x and 12.1.x) are not evaluated by F5 and will not receive patches; treat any such devices as permanently vulnerable.
  • ·A wide range of BIG-IP product lines are affected, including AAM, AFM, APM, ASM, Advanced WAF, Analytics, DHD, DNS, FPS, GTM, LTM, Link Controller, PEM, and SSLO — ensure all product variants are assessed, not just LTM.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.