First published: Wed Mar 31 2021(Updated: )
On all 7.x versions (fixed in 8.0.0), when set up for auto failover, a BIG-IQ Data Collection Device (DCD) cluster member that receives an undisclosed message may cause the corosync process to abort. This behavior may lead to a denial-of-service (DoS) and impact the stability of a BIG-IQ high availability (HA) cluster. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP and BIG-IQ Centralized Management | >=7.0.0<8.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22996 is a vulnerability on F5 BIG-IQ Centralized Management versions 7.x that can cause a denial-of-service (DoS) condition when set up for auto failover.
CVE-2021-22996 has a severity rating of 7.5 (High).
CVE-2021-22996 can impact the stability of a BIG-IQ high availability cluster by causing the corosync process to abort, resulting in a potential denial-of-service (DoS) condition.
All 7.x versions of F5 BIG-IQ Centralized Management are affected by CVE-2021-22996.
To fix CVE-2021-22996, upgrade to version 8.0.0 of F5 BIG-IQ Centralized Management.