CVE-2021-22996: High severity F5 BIG-IQ Centralized Management vulnerability
On all 7.x versions (fixed in 8.0.0), when set up for auto failover, a BIG-IQ Data Collection Device (DCD) cluster member that receives an undisclosed message may cause the corosync process to abort. This behavior may lead to a denial-of-service (DoS) and impact the stability of a BIG-IQ high availability (HA) cluster. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-22996?
CVE-2021-22996 is a vulnerability on F5 BIG-IQ Centralized Management versions 7.x that can cause a denial-of-service (DoS) condition when set up for auto failover.
What is the severity of CVE-2021-22996?
CVE-2021-22996 has a severity rating of 7.5 (High).
How can CVE-2021-22996 impact the stability of a BIG-IQ high availability cluster?
CVE-2021-22996 can impact the stability of a BIG-IQ high availability cluster by causing the corosync process to abort, resulting in a potential denial-of-service (DoS) condition.
Which versions of F5 BIG-IQ Centralized Management are affected by CVE-2021-22996?
All 7.x versions of F5 BIG-IQ Centralized Management are affected by CVE-2021-22996.
How can I fix CVE-2021-22996?
To fix CVE-2021-22996, upgrade to version 8.0.0 of F5 BIG-IQ Centralized Management.