These are `in the wild` vulnerabilities for existing software - refer to versions listed by F5 to see if you are impacted based on the versions you may be running. Details for the 2 most critical vulnerabilities can be found in the big tables on these articles:-
Recent news and incidents related to cybersecurity threats encompassing various events such as data breaches, cyber-attacks, security incidents, and vulnerabilities discovered.
March 20, 2021: On March 20, multiple stories reported the F5 vulnerabilities under `active attack`. FortiGuard IPS protects against 3 of the 4 critical CVEs identified (the 4th being 22987 which requires authentication). FortiGuard Labs Threat Signal Report is available from:
March 10, 2021: F5 announced several vulnerabilities and strongly urged customers to upgrade:
Mitigate security threats and vulnerabilities by leveraging the range of FortiGuard Services.
Assisted Response Services
Attack Surface Hardening
Information gathered from analyzing ongoing cybersecurity events including threat actors, their tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), malware and related vulnerabilities.
Sources of information in support and relation to this Outbreak and vendor.