CVE-2021-22991: F5 BIG-IP Traffic Management Microkernel Buffer Overflow
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Other sources
The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
F5 BIG-IPto a version that resolves this vulnerability.Fixed in 16.0.1.1 - Upgrade
Upgrade
F5 BIG-IPto a version that resolves this vulnerability.Fixed in 15.1.2.1 - Upgrade
Upgrade
F5 BIG-IPto a version that resolves this vulnerability.Fixed in 14.1.4 - Upgrade
Upgrade
F5 BIG-IPto a version that resolves this vulnerability.Fixed in 13.1.3.6 - Upgrade
Upgrade
F5 BIG-IPto a version that resolves this vulnerability.Fixed in 12.1.5.3 - Upgrade
Upgrade
F5 BIG-IP ASM Risk Engineto a version that resolves this vulnerability.Fixed in 16.0.1.1 - Upgrade
Upgrade
F5 BIG-IP ASM Risk Engineto a version that resolves this vulnerability.Fixed in 15.1.2.1 - Upgrade
Upgrade
F5 BIG-IP ASM Risk Engineto a version that resolves this vulnerability.Fixed in 14.1.4 - Upgrade
Upgrade
F5 BIG-IP ASM Risk Engineto a version that resolves this vulnerability.Fixed in 13.1.3.6 - Upgrade
Upgrade
F5 BIG-IP ASM Risk Engineto a version that resolves this vulnerability.Fixed in 12.1.5.3 - Upgrade
Upgrade
F5 BIG-IP Traffic Management Microkernelto a version that resolves this vulnerability.Fixed in 16.0.1.1 - Upgrade
Upgrade
F5 BIG-IP Traffic Management Microkernelto a version that resolves this vulnerability.Fixed in 15.1.2.1 - Upgrade
Upgrade
F5 BIG-IP Traffic Management Microkernelto a version that resolves this vulnerability.Fixed in 14.1.4 - Upgrade
Upgrade
F5 BIG-IP Traffic Management Microkernelto a version that resolves this vulnerability.Fixed in 13.1.3.6 - Upgrade
Upgrade
F5 BIG-IP Traffic Management Microkernelto a version that resolves this vulnerability.Fixed in 12.1.5.3
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22991?
The severity of CVE-2021-22991 is classified as critical due to the potential for unauthorized access and manipulation of data.
How do I fix CVE-2021-22991?
To fix CVE-2021-22991, upgrade your F5 BIG-IP software to the latest patched version that addresses this vulnerability.
What versions are affected by CVE-2021-22991?
CVE-2021-22991 affects F5 BIG-IP versions prior to 16.0.1.1, 15.1.2.1, 14.1.4, 13.1.3.6, and 12.1.5.3.
What types of software are vulnerable under CVE-2021-22991?
CVE-2021-22991 affects multiple F5 applications including BIG-IP Access Policy Manager, Advanced Firewall Manager, and Application Security Manager.
Is there a workaround for CVE-2021-22991?
Currently, the best practice is to apply the security update provided by F5 rather than relying on workarounds.