CVE-2021-22992
published 2021-03-31CVE-2021-22992: On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before…
PriorityP278critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
72.71%
99.4th percentile
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, a malicious HTTP response to an Advanced WAF/BIG-IP ASM virtual server with Login Page configured in its policy may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may allow remote code execution (RCE), leading to complete system compromise. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Affected
98 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | >= 11.6.1 < 11.6.5.3 | 11.6.5.3 |
| f5 | big-ip_access_policy_manager | >= 12.1.0 < 12.1.5.3 | 12.1.5.3 |
| f5 | big-ip_access_policy_manager | >= 13.1.0 < 13.1.3.6 | 13.1.3.6 |
| f5 | big-ip_access_policy_manager | >= 14.1.0 < 14.1.4 | 14.1.4 |
| f5 | big-ip_access_policy_manager | >= 15.1.0 < 15.1.2.1 | 15.1.2.1 |
| f5 | big-ip_access_policy_manager | >= 16.0.0 < 16.0.1.1 | 16.0.1.1 |
| f5 | big-ip_advanced_firewall_manager | >= 11.6.1 < 11.6.5.3 | 11.6.5.3 |
| f5 | big-ip_advanced_firewall_manager | >= 12.1.0 < 12.1.5.3 | 12.1.5.3 |
| f5 | big-ip_advanced_firewall_manager | >= 13.1.0 < 13.1.3.6 | 13.1.3.6 |
| f5 | big-ip_advanced_firewall_manager | >= 14.1.0 < 14.1.4 | 14.1.4 |
| f5 | big-ip_advanced_firewall_manager | >= 15.1.0 < 15.1.2.1 | 15.1.2.1 |
| f5 | big-ip_advanced_firewall_manager | >= 16.0.0 < 16.0.1.1 | 16.0.1.1 |
| f5 | big-ip_advanced_waf | — | — |
| f5 | big-ip_advanced_web_application_firewall | >= 11.6.1 < 11.6.5.3 | 11.6.5.3 |
| f5 | big-ip_advanced_web_application_firewall | >= 12.1.0 < 12.1.5.3 | 12.1.5.3 |
| f5 | big-ip_advanced_web_application_firewall | >= 13.1.0 < 13.1.3.6 | 13.1.3.6 |
| f5 | big-ip_advanced_web_application_firewall | >= 14.1.0 < 14.1.4 | 14.1.4 |
| f5 | big-ip_advanced_web_application_firewall | >= 15.1.0 < 15.1.2.1 | 15.1.2.1 |
| f5 | big-ip_advanced_web_application_firewall | >= 16.0.0 < 16.0.1.1 | 16.0.1.1 |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | >= 11.6.1 < 11.6.5.3 | 11.6.5.3 |
| f5 | big-ip_analytics | >= 12.1.0 < 12.1.5.3 | 12.1.5.3 |
| f5 | big-ip_analytics | >= 13.1.0 < 13.1.3.6 | 13.1.3.6 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered by a malicious HTTP response received by an Advanced WAF/BIG-IP ASM virtual server that has a Login Page configured in its policy. Detection should focus on anomalous or oversized HTTP responses directed at such virtual servers. ↗
- →Monitor BIG-IP ASM/Advanced WAF virtual servers with Login Page policies for unexpected crashes, restarts of ASM processes, or signs of memory corruption — indicators of a buffer overflow exploitation attempt (DoS or RCE). ↗
- →Scope detection to BIG-IP versions 11.6.1–11.6.5.3, 12.1.0–12.1.5.3, 13.1.0–13.1.3.6, 14.1.0–14.1.4, 15.1.0–15.1.2.1, and 16.0.0–16.0.1.1. Unpatched instances of these versions running ASM/Advanced WAF with Login Page policies are the attack surface. ↗
- ·The vulnerability is only exploitable on virtual servers where a Login Page is explicitly configured within the Advanced WAF/BIG-IP ASM policy. Virtual servers without this configuration are not affected. ↗
- ·A broad set of BIG-IP modules are listed as affected (AAM, AFM, APM, ASM, Advanced WAF, Analytics, DHD, DNS, FPS, GTM, LTM, Link Controller, PEM, SSL Orchestrator), but the actual attack vector specifically requires the Advanced WAF/ASM Login Page policy feature to be active. ↗
- ·Software versions that have reached End of Software Development (EoSD) are not evaluated and may also be vulnerable but are not covered by F5 advisories. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4f8p-5r29-jr72: On BIG-IP versions 16
ghsa_unreviewed·2022-05-24
CVE-2021-22992 [CRITICAL] CWE-120 GHSA-4f8p-5r29-jr72: On BIG-IP versions 16
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, a malicious HTTP response to an Advanced WAF/BIG-IP ASM virtual server with Login Page configured in its policy may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may allow remote code execution (RCE), leading to complete system compromise. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
F5
CVE-2021-22992: On BIG-IP versions 16
vendor_f5·2021-03-31·CVSS 9.8
CVE-2021-22992 [CRITICAL] CWE-120 CVE-2021-22992: On BIG-IP versions 16
CVE-2021-22992: On BIG-IP versions 16
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, a malicious HTTP response to an Advanced WAF/BIG-IP ASM virtual server with Login Page configured in its policy may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may allow remote code execution (RCE), leading to complete system compromise. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Advanced WAF, BIG-IP Analytics, BIG-IP DHD, BIG-IP DNS, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, Ssl Orchestrator
Affec
No detection rules found.
No public exploits indexed.
Fortinet
Defending Against Critical F5 Vulnerabilities | FortiGuard Labs
blogs_fortinet·2021-03-23·CVSS 9.8
[CRITICAL] Defending Against Critical F5 Vulnerabilities | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Defending Against Critical F5 Vulnerabilities
By FortiGuard Labs | March 23, 2021
FortiGuard Labs Threat Update
FortiGuard Labs has been actively monitoring efforts by attackers around the world to scan for and locate devices vulnerable to recently revealed flaws in the F5 BIG-IP/BIG-IQ family of application availability, access control, and security solutions. In addition, we have identified multiple instances of new proof of concept code being posted to known sites that could be used to exploit these vulnerabilities, further demonstrating the need to apply patches quickly.
F5 BIG-IP is an application delivery controller (ADC) used for load balancing and facilitating the movement of web traffic to its destination, and BIG-IQ provides centralized manage
Tenable
CVE-2021-22986: F5 Patches Several Critical Vulnerabilities in BIG-IP, BIG-IQ
blogs_tenable·2021-03-11·CVSS 9.8
[CRITICAL] CVE-2021-22986: F5 Patches Several Critical Vulnerabilities in BIG-IP, BIG-IQ
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
2021-03-31
Published