Skip to content
COOEY

EXPOSURES › CVE-2021-22991

CVE-2021-22991

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-01-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-22991 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

F5 BIG-IP Traffic Management Microkernel buffer overflow bypassed URL access controls and was actively exploited in the wild.

A buffer overflow in the F5 BIG-IP Traffic Management Microkernel allowed attackers to bypass URL-based access controls, leading to unauthorized access. This failure is critical for DIB organizations relying on F5 for network security, as it demonstrates the risk of unpatched, actively exploited vulnerabilities in critical infrastructure. Organizations must ensure timely patching and monitor for exploitation of known CVEs in their supply chain.

Shame score — A known buffer overflow was actively exploited in the wild, bypassing access controls and indicating a failure to patch a critical vulnerability before it was weaponized.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.