ZeroHour

CVE-2021-22991

KEVlarge

Buffer Overflow in F5 BIG-IP Traffic Management Microkernel (TMM)

CISA: F5 BIG-IP Traffic Management Microkernel Buffer Overflow

CVSS 3.1
9.8 critical
EPSS
61%p99
Published
()
KEV added
AI analysis

CVE-2021-22991 is a buffer overflow (CWE-119) in the URI normalization routine of F5 BIG-IP's Traffic Management Microkernel (TMM), the core component that processes traffic for all BIG-IP modules. It is triggered when undisclosed requests sent to a virtual server are incorrectly handled by TMM, causing a buffer overflow that typically results in a denial-of-service; in certain situations it may theoretically allow bypass of URL-based access controls or remote code execution. An unauthenticated, remote attacker (AV:N/PR:N/UI:N, CVSS 9.8) can reach the flaw simply by sending crafted requests to an affected virtual server. Organizations running BIG-IP versions 16.0.x, 15.1.x, 14.1.x, 13.1.x, or 12.1.x prior to the fixed releases are affected, including all listed BIG-IP modules (LTM, DNS, ASM, APM, AFM, AWAF, and others); versions past End of Software Development are not evaluated. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-01-18, and EPSS places it in the 99th percentile (61.1% chance of exploitation within 30 days), though no public PoC is known.

What to do: Upgrade affected BIG-IP systems to 16.0.1.1, 15.1.2.1, 14.1.4, 13.1.3.6, or 12.1.5.3 (or later) as applicable, per the vendor's instructions, as this is a CISA KEV requirement. Audit virtual servers exposed to untrusted traffic, since crafted requests to a virtual server are the trigger, and note that any BIG-IP modules on End-of-Software-Development branches are not evaluated and should be migrated. Because impact can include traffic-handling DoS and, in some situations, URL-based access control bypass or RCE, treat internet-facing BIG-IP appliances as priority targets for patching.

Affected
F5 BIG-IP Access Policy Manager16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3
F5 BIG-IP Advanced Firewall Manager16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3
F5 BIG-IP Advanced Web Application Firewall16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3
F5 BIG-IP Analytics16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3
F5 BIG-IP Application Acceleration Manager16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3
F5 BIG-IP Application Security Manager16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3
F5 BIG-IP DDoS Hybrid Defender16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3
F5 BIG-IP Domain Name System16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3
F5 BIG-IP Fraud Protection Service16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3
F5 BIG-IP Global Traffic Manager16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3
F5 BIG-IP Link Controller16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3
F5 BIG-IP Local Traffic Manager16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3
Estimated exposure
largetens of thousands of internet-exposed BIG-IP appliances (public scans show on the order of tens of thousands of exposed devices; total installed base is likely… — Public internet-wide scans (e.g., Shodan/Censys) routinely identify tens of thousands of F5 BIG-IP devices with exposed interfaces, and F5's position as a leading enterprise application delivery controller implies a substantially larger…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

CISA Known Exploited Vulnerability
Affected
F5 BIG-IP Traffic Management Microkernel
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
f5
Products
big-ip access policy manager, big-ip advanced firewall manager, big-ip advanced web application firewall, big-ip analytics, big-ip application acceleration manager, big-ip application security manager, big-ip ddos hybrid defender, big-ip domain name system, big-ip fraud protection service, big-ip global traffic manager, big-ip link controller, big-ip local traffic manager
Weakness
CWE-119
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news