Skip to main content
All vulnerabilities
CVE-2021-22986 Known ransomware use

F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

F5BIG-IP and BIG-IQ Centralized Management

Added to KEV catalog
3 November 2021
Federal remediation due date
17 November 2021
Weakness classification (CWE)
CWE-863

CISA Description

F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.

Required action

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2021-22986

Confirm Your Exposure

Is this vulnerability present in your environment?

CRS delivers independent VAPT assessments that identify exactly which known-exploited vulnerabilities exist in your network, applications, and infrastructure.

Explore VAPT Services