CVE-2024-21771: F5 AFM Signature Matching Vulnerability
For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic against signatures, resulting in Traffic Management Microkernel (TMM) restarting and traffic disruption.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
F5 BIG-IP (AFM + IPS)to a version that resolves this vulnerability.Fixed in 17.1.1 - Upgrade
Upgrade
F5 BIG-IP (AFM + IPS)to a version that resolves this vulnerability.Fixed in 16.1.4 - Upgrade
Upgrade
F5 BIG-IP (AFM + IPS)to a version that resolves this vulnerability.Fixed in 15.1.9
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21771?
CVE-2024-21771 is classified as a high severity vulnerability due to the potential for traffic disruption.
How do I fix CVE-2024-21771?
To fix CVE-2024-21771, upgrade F5 BIG-IP (AFM + IPS) to a version that includes the remedy for this vulnerability.
Which versions are affected by CVE-2024-21771?
CVE-2024-21771 affects F5 BIG-IP (AFM + IPS) versions 15.1.0 through 15.1.8, 16.1.0 through 16.1.3, and 17.1.0.
What symptoms indicate CVE-2024-21771 is affecting my system?
Symptoms of CVE-2024-21771 may include excessive time matching traffic against signatures leading to Traffic Management Microkernel (TMM) restarts.
Is there a workaround for CVE-2024-21771?
No specific workaround for CVE-2024-21771 is provided, and upgrading to a patched version is recommended.