CVE-2021-22991
KEVlargeBuffer Overflow in F5 BIG-IP Traffic Management Microkernel (TMM)
CISA: F5 BIG-IP Traffic Management Microkernel Buffer Overflow
CVE-2021-22991 is a buffer overflow (CWE-119) in the URI normalization routine of F5 BIG-IP's Traffic Management Microkernel (TMM), the core component that processes traffic for all BIG-IP modules. It is triggered when undisclosed requests sent to a virtual server are incorrectly handled by TMM, causing a buffer overflow that typically results in a denial-of-service; in certain situations it may theoretically allow bypass of URL-based access controls or remote code execution. An unauthenticated, remote attacker (AV:N/PR:N/UI:N, CVSS 9.8) can reach the flaw simply by sending crafted requests to an affected virtual server. Organizations running BIG-IP versions 16.0.x, 15.1.x, 14.1.x, 13.1.x, or 12.1.x prior to the fixed releases are affected, including all listed BIG-IP modules (LTM, DNS, ASM, APM, AFM, AWAF, and others); versions past End of Software Development are not evaluated. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-01-18, and EPSS places it in the 99th percentile (61.1% chance of exploitation within 30 days), though no public PoC is known.
What to do: Upgrade affected BIG-IP systems to 16.0.1.1, 15.1.2.1, 14.1.4, 13.1.3.6, or 12.1.5.3 (or later) as applicable, per the vendor's instructions, as this is a CISA KEV requirement. Audit virtual servers exposed to untrusted traffic, since crafted requests to a virtual server are the trigger, and note that any BIG-IP modules on End-of-Software-Development branches are not evaluated and should be migrated. Because impact can include traffic-handling DoS and, in some situations, URL-based access control bypass or RCE, treat internet-facing BIG-IP appliances as priority targets for patching.
| F5 BIG-IP Access Policy Manager | 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3 |
| F5 BIG-IP Advanced Firewall Manager | 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3 |
| F5 BIG-IP Advanced Web Application Firewall | 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3 |
| F5 BIG-IP Analytics | 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3 |
| F5 BIG-IP Application Acceleration Manager | 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3 |
| F5 BIG-IP Application Security Manager | 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3 |
| F5 BIG-IP DDoS Hybrid Defender | 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3 |
| F5 BIG-IP Domain Name System | 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3 |
| F5 BIG-IP Fraud Protection Service | 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3 |
| F5 BIG-IP Global Traffic Manager | 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3 |
| F5 BIG-IP Link Controller | 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3 |
| F5 BIG-IP Local Traffic Manager | 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
- Affected
- F5 BIG-IP Traffic Management Microkernel
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- f5
- Products
- big-ip access policy manager, big-ip advanced firewall manager, big-ip advanced web application firewall, big-ip analytics, big-ip application acceleration manager, big-ip application security manager, big-ip ddos hybrid defender, big-ip domain name system, big-ip fraud protection service, big-ip global traffic manager, big-ip link controller, big-ip local traffic manager
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H