S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-22986 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in F5 BIG-IP, BIG-IQ affects v. BIG-IP 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3; BIG-IQ 7.1.0.x before 7.1.0.3, 7.0.0.x before 7.0.0.2.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-22986
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
BIG-IP; BIG-IQby n/a
BIG-IP 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3
Updated Aug 21, 2026View on NVD →
Detail

F5 BIG-IP and BIG-IQ are powerful tools designed for the management and optimization of network applications. They are used by organizations of all sizes, including government institutions, healthcare facilities, and financial services companies. With the help of F5 BIG-IP and BIG-IQ, businesses can easily manage and distribute their web traffic, secure their applications, and optimize their performance with customizable policies. These products also provide advanced analytics and monitoring capabilities.

One of the most concerning issues detected in F5 BIG-IP and BIG-IQ is CVE-2021-22986, which is an unauthenticated remote command execution vulnerability in the iControl REST interface. This vulnerability has been found in BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6 and 12.1.x before 12.1.5.3, as well as BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2.

When exploited, CVE-2021-22986 can lead to serious consequences, including unauthorized access to sensitive data, network breaches, and system crashes. Attackers can exploit this vulnerability to execute arbitrary commands on the target device, potentially allowing them to gain full control over the system. This can result in a significant loss of data, service disruption, and reputational damage for the impacted organization.

With the pro features of the s4e.io platform, individuals and organizations can easily and quickly learn about vulnerabilities in their digital assets. With comprehensive vulnerability scanning, detailed reporting, and expert guidance, s4e.io provides peace of mind and proactive protection for businesses of all sizes. Don't wait until it's too late – take action today to protect your valuable digital assets from cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, F5 recommends the following precautions:

  • Upgrade to a non-vulnerable software version as soon as possible.
  • Restrict access to the iControl REST interface by enabling the IP address-based access control list (ACL).
  • Implement VPN access to the iControl REST interface to limit exposure.
  • Monitor the logs for any suspicious activity that could indicate an attempted exploit of CVE-2021-22986.
  • Consider implementing additional security measures, such as an intrusion prevention system (IPS) or an advanced threat detection solution.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-22986 scanner - Remote Code Execution (RCE) vulnerability in F5 BIG-IP, BIG-IQ | S4E