CVE-2021-22986: presente nel catalogo CISA KEV CVE-2021-22986 · CVSS 9.8 CRITICAL · EPSS 99.9% · KEV 2021-11-03 · patch disponibile
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
CVE-2021-22986 viene sfruttato? Inserito nel catalogo CISA KEV il 2021-11-03. Scadenza di remediation federale: 2021-11-17. Oltre quella data da 1779 giorni. Usato in campagne ransomware. EPSS stima la probabilità di sfruttamento nei prossimi 30 giorni al 99.9%. Codice di exploit pubblico: integrato in uno strumento pubblico. Esistono regole di detection pubbliche. Quali prodotti e versioni sono interessati? BIG-IP; BIG-IQ · BIG-IP 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, BIG-IQ 7.1.0.x before 7.1.0.3, 7.0.0.x before 7.0.0.2 f5 · big-ip access policy manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip advanced firewall manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip advanced web application firewall · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip analytics · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip application acceleration manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip application security manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip ddos hybrid defender · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip domain name system · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip fraud protection service · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip global traffic manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip link controller · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip local traffic manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip policy enforcement manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-iq centralized management · >= 6.0.0, < 6.1.0, >= 7.0.0, < 7.0.0.2, >= 7.1.0, < 7.1.0.3 f5 · ssl orchestrator · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 Esiste una patch? big-ip access policy manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip advanced firewall manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip advanced web application firewall 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip analytics 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip application acceleration manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip application security manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip ddos hybrid defender 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip domain name system 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip fraud protection service 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip global traffic manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip link controller 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip local traffic manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip policy enforcement manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-iq centralized management 6.1.0, 7.0.0.2, 7.1.0.3 ssl orchestrator 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more Cosa ha pubblicato PlainSec su CVE-2021-22986 Fonti primarie KEV ed EPSS vengono ricontrollati ogni giorno. Scheda aggiornata il 2026-09-15.
CVE-2021-22986: presente nel catalogo CISA KEV CVE-2021-22986 · CVSS 9.8 CRITICAL · EPSS 99.9% · KEV 2021-11-03 · patch disponibile
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
CVE-2021-22986 viene sfruttato? Inserito nel catalogo CISA KEV il 2021-11-03. Scadenza di remediation federale: 2021-11-17. Oltre quella data da 1779 giorni. Usato in campagne ransomware. EPSS stima la probabilità di sfruttamento nei prossimi 30 giorni al 99.9%. Codice di exploit pubblico: integrato in uno strumento pubblico. Esistono regole di detection pubbliche. Quali prodotti e versioni sono interessati? BIG-IP; BIG-IQ · BIG-IP 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, BIG-IQ 7.1.0.x before 7.1.0.3, 7.0.0.x before 7.0.0.2 f5 · big-ip access policy manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip advanced firewall manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip advanced web application firewall · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip analytics · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip application acceleration manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip application security manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip ddos hybrid defender · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip domain name system · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip fraud protection service · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip global traffic manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip link controller · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip local traffic manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-ip policy enforcement manager · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 f5 · big-iq centralized management · >= 6.0.0, < 6.1.0, >= 7.0.0, < 7.0.0.2, >= 7.1.0, < 7.1.0.3 f5 · ssl orchestrator · >= 12.1.0, < 12.1.5.3, >= 13.1.0, < 13.1.3.6, >= 14.1.0, < 14.1.4, >= 15.1.0, < 15.1.2.1, >= 16.0.0, < 16.0.1.1 Esiste una patch? big-ip access policy manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip advanced firewall manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip advanced web application firewall 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip analytics 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip application acceleration manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip application security manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip ddos hybrid defender 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip domain name system 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip fraud protection service 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip global traffic manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip link controller 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip local traffic manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-ip policy enforcement manager 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more big-iq centralized management 6.1.0, 7.0.0.2, 7.1.0.3 ssl orchestrator 12.1.5.3, 13.1.3.6, 14.1.4, 15.1.2.1, +1 more Cosa ha pubblicato PlainSec su CVE-2021-22986 Fonti primarie KEV ed EPSS vengono ricontrollati ogni giorno. Scheda aggiornata il 2026-09-15.