EXPOSURES › CVE-2021-22991
CVE-2021-22991
HIGH ⌖ ON CISA KEV · EXPLOITEDF5 BIG-IP Traffic Management Microkernel buffer overflow bypassed URL access controls and was actively exploited in the wild.
A buffer overflow in the F5 BIG-IP Traffic Management Microkernel allowed attackers to bypass URL-based access controls, leading to unauthorized access. This failure is critical for DIB organizations relying on F5 for network security, as it demonstrates the risk of unpatched, actively exploited vulnerabilities in critical infrastructure. Organizations must ensure timely patching and monitor for exploitation of known CVEs in their supply chain.
Shame score — A known buffer overflow was actively exploited in the wild, bypassing access controls and indicating a failure to patch a critical vulnerability before it was weaponized.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.