CVE-2021-22989
9.1
CRITICAL · CVSS 3.1 · EPSS 8.8% (pctl 95)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, when running in Appliance mode with Advanced WAF or BIG-IP ASM provisioned, the TMUI, also referred to as the Configuration utility, has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 8.84% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-03-31 |
| Last modified | 2026-06-17 |
Affected (14)
| Vendor | Product |
|---|---|
| f5 | big-ip access policy manager |
| f5 | big-ip advanced firewall manager |
| f5 | big-ip advanced web application firewall |
| f5 | big-ip analytics |
| f5 | big-ip application acceleration manager |
| f5 | big-ip application security manager |
| f5 | big-ip ddos hybrid defender |
| f5 | big-ip domain name system |
| f5 | big-ip fraud protection service |
| f5 | big-ip global traffic manager |
| f5 | big-ip link controller |
| f5 | big-ip local traffic manager |
| f5 | big-ip policy enforcement manager |
| f5 | ssl orchestrator |
References
→ the Explorer · watch your stack · NVD