CVE-2021-23035: Input Validation
On BIG-IP 14.1.x before 14.1.4.4, when an HTTP profile is configured on a virtual server, after a specific sequence of packets, chunked responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-23035?
CVE-2021-23035 has a high severity rating as it can lead to service disruption due to Traffic Management Microkernel termination.
How do I fix CVE-2021-23035?
To fix CVE-2021-23035, upgrade your F5 BIG-IP software to version 14.1.4.4 or later.
Which F5 BIG-IP versions are affected by CVE-2021-23035?
CVE-2021-23035 affects all BIG-IP versions from 14.1.0 to 14.1.4.4, inclusive.
What impact does CVE-2021-23035 have on F5 BIG-IP services?
CVE-2021-23035 can cause unexpected termination of service processes, disrupting HTTP traffic handling.
Is there a workaround for CVE-2021-23035?
There are no specific workarounds mentioned for CVE-2021-23035; upgrading is recommended.