CRITICAL

CVE-2021-22991

F5 Big Ip Access Policy Manager 2021-03-31 CVSS v3.1
CVSS
9.8
KEV

Description

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

Summary dbcve.org

A buffer overflow vulnerability in the BIG-IP Traffic Management Microkernel (TMM) URI normalization component allows specially crafted undisclosed requests to virtual servers to trigger overflow conditions, potentially causing denial of service, URL-based access control bypass, or remote code execution.

Mitigation

Apply vendor patches (16.0.1.1, 15.1.2.1, 14.1.4, 13.1.3.6, or 12.1.5.3) to all affected BIG-IP devices. Restrict external access to vulnerable virtual servers until patching is complete.

Weakness (CWE)

CWE-119 Memory Buffer Bounds Error

EPSS Score

61.06%
Probability of exploitation in next 30 days
99.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE