F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability
F5 — BIG-IP and BIG-IQ Centralized Management
- Added to KEV catalog
- 3 November 2021
- Federal remediation due date
- 17 November 2021
- Weakness classification (CWE)
- CWE-863
CISA Description
F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.
Required action
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2021-22986
More F5 Vulnerabilities
F5 BIG-IP Stack-Based Buffer Overflow Vulnerability
F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
F5 BIG-IP Configuration Utility SQL Injection Vulnerability
F5 BIG-IP Missing Authentication Vulnerability
F5 BIG-IP Traffic Management Microkernel Buffer Overflow
Is this vulnerability present in your environment?
CRS delivers independent VAPT assessments that identify exactly which known-exploited vulnerabilities exist in your network, applications, and infrastructure.
Explore VAPT Services