CVE-2021-23032: Input Validation
On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a BIG-IP DNS system is configured with non-default Wide IP and pool settings, undisclosed DNS responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-23032?
CVE-2021-23032 has a CVSS score indicating a medium severity vulnerability that affects F5 BIG-IP DNS systems.
How do I fix CVE-2021-23032?
To fix CVE-2021-23032, upgrade your F5 BIG-IP DNS to the latest version that is not affected.
What are the affected versions in CVE-2021-23032?
CVE-2021-23032 affects versions 12.1.x to 12.1.6, 13.1.x, 14.1.x up to 14.1.4.4, 15.1.x up to 15.1.3.1, and 16.0.x up to 16.1.0.
What is the impact of CVE-2021-23032 on my system?
The impact of CVE-2021-23032 can cause the Traffic Management Microkernel (TMM) to terminate, disrupting DNS service.
Who is affected by CVE-2021-23032?
Network administrators using F5 BIG-IP DNS with non-default Wide IP and pool settings are affected by CVE-2021-23032.