cbcvebase.
CVE-2021-22992
published 2021-03-31

CVE-2021-22992: On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before…

PriorityP278critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
72.71%
99.4th percentile
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, a malicious HTTP response to an Advanced WAF/BIG-IP ASM virtual server with Login Page configured in its policy may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may allow remote code execution (RCE), leading to complete system compromise. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

Affected

98 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip_aam
f5big-ip_access_policy_manager>= 11.6.1 < 11.6.5.311.6.5.3
f5big-ip_access_policy_manager>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_access_policy_manager>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_access_policy_manager>= 14.1.0 < 14.1.414.1.4
f5big-ip_access_policy_manager>= 15.1.0 < 15.1.2.115.1.2.1
f5big-ip_access_policy_manager>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_advanced_firewall_manager>= 11.6.1 < 11.6.5.311.6.5.3
f5big-ip_advanced_firewall_manager>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_advanced_firewall_manager>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_advanced_firewall_manager>= 14.1.0 < 14.1.414.1.4
f5big-ip_advanced_firewall_manager>= 15.1.0 < 15.1.2.115.1.2.1
f5big-ip_advanced_firewall_manager>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_advanced_waf
f5big-ip_advanced_web_application_firewall>= 11.6.1 < 11.6.5.311.6.5.3
f5big-ip_advanced_web_application_firewall>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_advanced_web_application_firewall>= 13.1.0 < 13.1.3.613.1.3.6
f5big-ip_advanced_web_application_firewall>= 14.1.0 < 14.1.414.1.4
f5big-ip_advanced_web_application_firewall>= 15.1.0 < 15.1.2.115.1.2.1
f5big-ip_advanced_web_application_firewall>= 16.0.0 < 16.0.1.116.0.1.1
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics>= 11.6.1 < 11.6.5.311.6.5.3
f5big-ip_analytics>= 12.1.0 < 12.1.5.312.1.5.3
f5big-ip_analytics>= 13.1.0 < 13.1.3.613.1.3.6

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered by a malicious HTTP response received by an Advanced WAF/BIG-IP ASM virtual server that has a Login Page configured in its policy. Detection should focus on anomalous or oversized HTTP responses directed at such virtual servers.
  • Monitor BIG-IP ASM/Advanced WAF virtual servers with Login Page policies for unexpected crashes, restarts of ASM processes, or signs of memory corruption — indicators of a buffer overflow exploitation attempt (DoS or RCE).
  • Scope detection to BIG-IP versions 11.6.1–11.6.5.3, 12.1.0–12.1.5.3, 13.1.0–13.1.3.6, 14.1.0–14.1.4, 15.1.0–15.1.2.1, and 16.0.0–16.0.1.1. Unpatched instances of these versions running ASM/Advanced WAF with Login Page policies are the attack surface.
  • ·The vulnerability is only exploitable on virtual servers where a Login Page is explicitly configured within the Advanced WAF/BIG-IP ASM policy. Virtual servers without this configuration are not affected.
  • ·A broad set of BIG-IP modules are listed as affected (AAM, AFM, APM, ASM, Advanced WAF, Analytics, DHD, DNS, FPS, GTM, LTM, Link Controller, PEM, SSL Orchestrator), but the actual attack vector specifically requires the Advanced WAF/ASM Login Page policy feature to be active.
  • ·Software versions that have reached End of Software Development (EoSD) are not evaluated and may also be vulnerable but are not covered by F5 advisories.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.