RIFT: Detection capabilities for recent F5 BIG-IP/BIG-IQ iControl REST API vulnerabilities CVE-2021-22986
ID: 83271498-57fa-5924-9dcd-f6c40efb3843
STIX ID: report--83271498-57fa-5924-9dcd-f6c40efb3843
Feed Name: NCC Research
**Executive summary:** NCC Group observed active exploitation attempts against F5 BIG‑IP/BIG‑IQ iControl REST API vulnerabilities (CVE-2021-22986 and related CVEs), reproduced the SSRF-based authentication bypass that leads to authenticated remote code execution via the tm/util/bash endpoint, published log and network detection artifacts (restjavad, restjavad-audit, audit entries) and Suricata rules, and noted the release of a public exploit—recommend immediate monitoring, relevant log inspection, and patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
