CVE-2021-22991 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 61.1% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2022-02-01.
Description
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 61.06% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | yes — remediate by 2022-02-01 |
| Public exploit | none known |
| Published | 2021-03-31 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | F5 BIG-IP Traffic Management Microkernel Buffer Overflow |
|---|---|
| Added | 2022-01-18 |
| Due | 2022-02-01 |
| Vendor / product | F5 / BIG-IP Traffic Management Microkernel |
| Ransomware use | none reported |
Affected (14)
| Vendor | Product |
|---|---|
| f5 | big-ip access policy manager |
| f5 | big-ip advanced firewall manager |
| f5 | big-ip advanced web application firewall |
| f5 | big-ip analytics |
| f5 | big-ip application acceleration manager |
| f5 | big-ip application security manager |
| f5 | big-ip ddos hybrid defender |
| f5 | big-ip domain name system |
| f5 | big-ip fraud protection service |
| f5 | big-ip global traffic manager |
| f5 | big-ip link controller |
| f5 | big-ip local traffic manager |
| f5 | big-ip policy enforcement manager |
| f5 | ssl orchestrator |
References
→ the Explorer · watch your stack · NVD