← KEV catalog
CISA known exploited vulnerability

CVE-2021-22986

F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

SOURCE FACT

F5 · BIG-IP and BIG-IQ Centralized Management

F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2021-22986

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?