cbcvebase.
CVE-2021-22991
published 2021-03-31

CVE-2021-22991: On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed…

PriorityP195critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-02-01
Exploited in the wild
EPSS
61.06%
99.1th percentile
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

Affected

85 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip_aam
f5big-ip_access_policy_manager
f5big-ip_access_policy_manager>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_access_policy_manager>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_access_policy_manager>= 14.1.0 < 14.1.414.1.4
f5big-ip_access_policy_manager>= 15.1.0 < 15.1.2.115.1.2.1
f5big-ip_access_policy_manager>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_advanced_firewall_manager>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_advanced_firewall_manager>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_advanced_firewall_manager>= 14.1.0 < 14.1.414.1.4
f5big-ip_advanced_firewall_manager>= 15.1.0 < 15.1.2.115.1.2.1
f5big-ip_advanced_firewall_manager>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_advanced_waf
f5big-ip_advanced_web_application_firewall>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_advanced_web_application_firewall>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_advanced_web_application_firewall>= 14.1.0 < 14.1.414.1.4
f5big-ip_advanced_web_application_firewall>= 15.1.0 < 15.1.2.115.1.2.1
f5big-ip_advanced_web_application_firewall>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_analytics>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_analytics>= 14.1.0 < 14.1.414.1.4
f5big-ip_analytics>= 15.1.0 < 15.1.2.115.1.2.1
f5big-ip_analytics>= 16.0.0 < 16.0.1.116.0.1.1

Detection & IOCsextracted from sources · hover to see the quote

snort
alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible F5 BIG-IP Infoleak and Out-of-Bounds Write Inbound (CVE-2021-22991)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"|3a 2f 2f 5b|"; fast_pattern; content:"|5d|"; endswith; reference:url,bugs.chromium.org/p/project-zero/issues/detail?id=2126; reference:cve,2021-22991; classtype:attempted-admin; sid:2032173; rev:1; metadata:attack_target Server, created_at 2021_03_18, cve CVE_2021_22991, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_03_18;)
bytes
|3a 2f 2f 5b|
  • Look for inbound HTTP GET requests to virtual servers where the URI contains the byte sequence |3a 2f 2f 5b| (://[) with a closing |5d| (]) at the end — this pattern targets the TMM URI normalization buffer overflow via malformed URI with bracket notation.
  • The vulnerability is triggered by undisclosed requests to a BIG-IP virtual server that are incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization — monitor TMM process crashes or unexpected restarts as a DoS indicator.
  • In addition to DoS, successful exploitation may allow bypass of URL-based access controls or RCE — correlate TMM crashes with any subsequent unauthorized access to protected URL paths.
  • ·Affected BIG-IP versions span multiple branches; ensure patching targets all in-scope versions: 12.1.0–12.1.5.3, 13.1.0–13.1.3.6, 14.1.0–14.1.4, 15.1.0–15.1.2.1, and 16.0.0–16.0.1.1.
  • ·The vulnerability affects a broad set of BIG-IP modules (AAM, AFM, APM, ASM, Advanced WAF, Analytics, DHD, DNS, FPS, GTM, LTM, Link Controller, PEM, SSL Orchestrator) — detection and patching scope must cover all deployed modules.
  • ·BIG-IP versions that have reached End of Software Development (EoSD) are not evaluated for this CVE — do not assume unpatched EoSD versions are safe; they remain vulnerable.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.