NVD disclosure day

Published threat advisories for March 31, 2021

CVE advisoryKnown Exploit

CVE-2021-22991

F5 BIG-IP Systems Vulnerable to Remote Code Execution and Denial of Service

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Certain F5 BIG-IP systems are affected by a vulnerability that can lead to denial-of-service or bypass of access controls. This may impact system availability and data integrity. The risk to business operations is heightened as this vulnerability can be exploited remotely.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-21975

VMware vRealize Operations Manager API Credential Theft Risk.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A Server-Side Request Forgery vulnerability in the VMware vRealize Operations Manager API allows a malicious actor with network access to steal administrative credentials. This poses a business risk of unauthorized access and potential data compromise.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-22986

F5 BIG-IP and BIG-IQ Remote Command Execution Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

F5 BIG-IP and BIG-IQ products have a remote command execution vulnerability in the iControl REST interface. This could allow attackers to execute commands, impacting system integrity and data security. The business risk is high due to the potential for unauthorized access and control.

• CISA KEV