← Back to CVE List
Vulnerability Analysis

CVE-2021-22991

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

CISA KEV
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
Temporal Score:-
EPSS:61.06%

Threat Intelligence Signals

CISA KEV
YES
KEV Date Added
2022-01-18
Ransomware Use
Unknown
KEV Due Date
2022-02-01
VulnCheck In-the-Wild
No
Nuclei Template
No
EPSS Score
61.064%
EPSS Percentile
99.0th pct
GitHub Severity
CRITICAL
SSVC Exploitation
SSVC Automatable
Vulnerability Class

Identity & Timeline

Status-
Assigning Authority-
CVSS Version / Source-
Reserved-
Published-
Patch Date (date_public)-
Exploit DB Date-
First GitHub PoC Date-
Last Updated-
Time to Patch (Days to fix)-
Exploit Release Gap-
PoC Release Gap-
Exploit DB ReferencesNone identified

Affected Products & Versions

Vendor Product Affected Versions
No affected products specified.

References

No reference links found.

LINK COPIED TO CLIPBOARD