EXPOSURES › CVE-2021-22986
CVE-2021-22986
CRITICAL ⌖ ON CISA KEV · EXPLOITEDF5 BIG-IP devices had a critical, unauthenticated remote code execution vulnerability actively exploited by ransomware actors, allowing attackers to execute arbitrary commands on affected systems.
The F5 iControl REST interface vulnerability (CVE-2021-22986) enabled unauthenticated attackers to execute system commands, create/delete files, and disable services, which was actively exploited in ransomware attacks. DIB organizations using BIG-IP or BIG-IQ must immediately patch and review network access controls. Failure to do so exposes systems to compromise and non-compliance with NIST 800-171.
Shame score — The vulnerability's ease of exploitation, lack of authentication, and active ransomware exploitation demonstrate significant negligence and a serious risk to DIB partners.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.