CVE-2021-23051: Input Validation
On BIG-IP versions 15.1.0.4 through 15.1.3, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP on Amazon Web Services (AWS) systems, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This is due to an incomplete fix for CVE-2020-5862. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-23051.
Which software versions are affected by this vulnerability?
BIG-IP versions 15.1.0.4 through 15.1.3 are affected by this vulnerability.
What is the severity of CVE-2021-23051?
The severity of CVE-2021-23051 is high, with a severity value of 7.5.
How does this vulnerability occur?
This vulnerability occurs when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP on Amazon Web Services (AWS) systems.
How can this vulnerability be exploited?
Undisclosed requests can be used to exploit this vulnerability and cause the Traffic Management Microkernel (TMM) to terminate.