← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-22987

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3 when running in Appliance mode, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

No Active Exploit Signals
CVSS Base Score
9.9
CRITICAL
EPSS Probability:13.67%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
f5 big-ip_access_policy_manager all
f5 big-ip_advanced_firewall_manager all
f5 big-ip_advanced_web_application_firewall all
f5 big-ip_analytics all
f5 big-ip_application_acceleration_manager all
f5 big-ip_application_security_manager all
f5 big-ip_ddos_hybrid_defender all
f5 big-ip_domain_name_system all
f5 big-ip_fraud_protection_service all
f5 big-ip_global_traffic_manager all
f5 big-ip_link_controller all
f5 big-ip_local_traffic_manager all
f5 big-ip_policy_enforcement_manager all
f5 ssl_orchestrator all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
13.672%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityF5, Inc. · Vendor · USA
Reserved2021-01-06T00:00:00
Published2021-03-31T16:43:17
Last Updated2024-08-03T18:58:26

LINK COPIED TO CLIPBOARD