Skip to content
COOEY

EXPOSURES › CVE-2021-22986

CVE-2021-22986

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-22986 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

F5 BIG-IP devices had a critical, unauthenticated remote code execution vulnerability actively exploited by ransomware actors, allowing attackers to execute arbitrary commands on affected systems.

The F5 iControl REST interface vulnerability (CVE-2021-22986) enabled unauthenticated attackers to execute system commands, create/delete files, and disable services, which was actively exploited in ransomware attacks. DIB organizations using BIG-IP or BIG-IQ must immediately patch and review network access controls. Failure to do so exposes systems to compromise and non-compliance with NIST 800-171.

Shame score — The vulnerability's ease of exploitation, lack of authentication, and active ransomware exploitation demonstrate significant negligence and a serious risk to DIB partners.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
cooey ↗ severe-fallout -1.00
negative
"…"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.