TROYANOSYVIRUS
Retour aux CVEs

CVE-2021-22991

CRITICALCISA KEV
9.8

Description

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

Details CVE

Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie3/31/2021
Derniere modification10/27/2025
Sourcekev
Observations honeypot0

CISA KEV

FournisseurF5
ProduitBIG-IP Traffic Management Microkernel
Nom vulnerabiliteF5 BIG-IP Traffic Management Microkernel Buffer Overflow
Date ajout KEV2022-01-18
Date limite remediation2022-02-01
Utilise dans ransomwareUnknown

Produits affectes

f5:big-ip_access_policy_managerf5:big-ip_advanced_firewall_managerf5:big-ip_advanced_web_application_firewallf5:big-ip_analyticsf5:big-ip_application_acceleration_managerf5:big-ip_application_security_managerf5:big-ip_ddos_hybrid_defenderf5:big-ip_domain_name_systemf5:big-ip_fraud_protection_servicef5:big-ip_global_traffic_managerf5:big-ip_link_controllerf5:big-ip_local_traffic_managerf5:big-ip_policy_enforcement_managerf5:ssl_orchestrator

Faiblesses (CWE)

CWE-119CWE-119

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.