Vulnerability threat dossier

CVE-2021-22986

f5big-ip access policy manager

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

VTP deterministic threat50.0of 100 · CVSS excluded

VTP analyst assessment

F5 BIG-IP iControl REST remote code execution

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence85%
Public exploitation · VTP factKEV

Assessment

CVE-2021-22986 allows unauthenticated remote command execution through the BIG-IP and BIG-IQ iControl REST interface on affected versions. CISA KEV lists known exploitation and known ransomware campaign use.

Why it matters

  • BIG-IP and BIG-IQ commonly provide central application-delivery and management functions.
  • An exposed vulnerable iControl REST interface could provide an attacker with remote code execution.

Evidence

0 record references and 0 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

No CVE-specific current campaign or exploit detail is supplied.

First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

Next watchpoint

If you use affected F5 BIG-IP or BIG-IQ versions, upgrade to F5's fixed release and restrict iControl REST access.

AI baseline history (2)
  1. BASELINE ASSESSED
    F5 BIG-IP iControl REST remote code executiongpt-5.6-terra · low
  2. BASELINE ASSESSED
    F5 iControl REST unauthenticated command executiongpt-5.6-sol · high
Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityNONE KNOWNReliability not implied
EPSS1.00100th percentile · prediction
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
MEDIUM

Honeypot request semantics are potentially consistent with CVE-2021-22986. The match tolerates bounded payload variants and remains unconfirmed.

POTENTIALLY COMPATIBLETechnical consistency 80/100

Basis: deterministic technical candidate

Potentially consistent; exploitation not confirmedDisclosure embargo completed
MEDIUM

Honeypot request semantics are potentially consistent with CVE-2021-22986. The match tolerates bounded payload variants and remains unconfirmed.

POTENTIALLY COMPATIBLETechnical consistency 80/100

Basis: deterministic technical candidate

Potentially consistent; exploitation not confirmedDisclosure embargo completed
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 1.00; this is predictive context, not exploitation evidence.

  3. 03

    First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

02

Material change ledger

What changed

KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

1publications detected
1underlying evidence chains

0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

04

Event history

Threat timeline

  1. 00:0003 Nov
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Thai Broadband Provider Hacked via Fortinet Vulnerability

The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools. The post Thai Broadband Provider Hacked via Fortinet Vulnerability appeared first on SecurityWeek .

CVE-2018-13379CVE-2021-22986CVE-2022-1388CVE-2022-42475CVE-2023-27997CVE-2023-46747CVE-2024-21762
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score50.0vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction19.98 / 20
Exploit availability0 / 15
Source independence0 / 15
Intelligence recency0 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-918
CPE records
15
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.