On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HF5 Big Ip Access Policy Manager
APPF512.1.0 – 12.1.5.3 (excl.)13.1.0 – 13.1.3.6 (excl.)14.1.0 – 14.1.4 (excl.)15.1.0 – 15.1.2.1 (excl.)16.0.0 – 16.0.1.1 (excl.)F5 Big Ip Advanced Firewall Manager
APPF512.1.0 – 12.1.5.3 (excl.)13.1.0 – 13.1.3.6 (excl.)14.1.0 – 14.1.4 (excl.)15.1.0 – 15.1.2.1 (excl.)16.0.0 – 16.0.1.1 (excl.)F5 Big Ip Advanced Web Application Firewall
APPF512.1.0 – 12.1.5.3 (excl.)13.1.0 – 13.1.3.6 (excl.)14.1.0 – 14.1.4 (excl.)15.1.0 – 15.1.2.1 (excl.)16.0.0 – 16.0.1.1 (excl.)F5 Big Ip Analytics
APPF512.1.0 – 12.1.5.3 (excl.)13.1.0 – 13.1.3.6 (excl.)14.1.0 – 14.1.4 (excl.)15.1.0 – 15.1.2.1 (excl.)16.0.0 – 16.0.1.1 (excl.)F5 Big Ip Application Acceleration Manager
APPF512.1.0 – 12.1.5.3 (excl.)13.1.0 – 13.1.3.6 (excl.)14.1.0 – 14.1.4 (excl.)15.1.0 – 15.1.2.1 (excl.)16.0.0 – 16.0.1.1 (excl.)F5 Big Ip Application Security Manager
APPF512.1.0 – 12.1.5.3 (excl.)13.1.0 – 13.1.3.6 (excl.)14.1.0 – 14.1.4 (excl.)15.1.0 – 15.1.2.1 (excl.)16.0.0 – 16.0.1.1 (excl.)F5 Big Ip Ddos Hybrid Defender
APPF512.1.0 – 12.1.5.3 (excl.)13.1.0 – 13.1.3.6 (excl.)14.1.0 – 14.1.4 (excl.)15.1.0 – 15.1.2.1 (excl.)16.0.0 – 16.0.1.1 (excl.)F5 Big Ip Domain Name System
APPF512.1.0 – 12.1.5.3 (excl.)13.1.0 – 13.1.3.6 (excl.)14.1.0 – 14.1.4 (excl.)15.1.0 – 15.1.2.1 (excl.)16.0.0 – 16.0.1.1 (excl.)F5 Big Ip Fraud Protection Service
APPF512.1.0 – 12.1.5.3 (excl.)13.1.0 – 13.1.3.6 (excl.)14.1.0 – 14.1.4 (excl.)15.1.0 – 15.1.2.1 (excl.)16.0.0 – 16.0.1.1 (excl.)F5 Big Ip Global Traffic Manager
APPF512.1.0 – 12.1.5.3 (excl.)13.1.0 – 13.1.3.6 (excl.)14.1.0 – 14.1.4 (excl.)15.1.0 – 15.1.2.1 (excl.)16.0.0 – 16.0.1.1 (excl.)F5 Big Ip Link Controller
APPF512.1.0 – 12.1.5.3 (excl.)13.1.0 – 13.1.3.6 (excl.)14.1.0 – 14.1.4 (excl.)15.1.0 – 15.1.2.1 (excl.)16.0.0 – 16.0.1.1 (excl.)F5 Big Ip Local Traffic Manager
APPF512.1.0 – 12.1.5.3 (excl.)13.1.0 – 13.1.3.6 (excl.)14.1.0 – 14.1.4 (excl.)15.1.0 – 15.1.2.1 (excl.)16.0.0 – 16.0.1.1 (excl.)F5 Big Ip Policy Enforcement Manager
APPF512.1.0 – 12.1.5.3 (excl.)13.1.0 – 13.1.3.6 (excl.)14.1.0 – 14.1.4 (excl.)15.1.0 – 15.1.2.1 (excl.)16.0.0 – 16.0.1.1 (excl.)F5 Ssl Orchestrator
APPF512.1.0 – 12.1.5.3 (excl.)13.1.0 – 13.1.3.6 (excl.)14.1.0 – 14.1.4 (excl.)15.1.0 – 15.1.2.1 (excl.)16.0.0 – 16.0.1.1 (excl.)
CISA KEV — detailsi
- Vendori
- F5 ↗
- Producti
- BIG-IP Traffic Management Microkernel
- Added to KEVi
- January 18, 2022
- Remediation deadline (US Federal)i
- February 1, 2022(overdue)
Apply updates per vendor instructions.
The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.
Related vulnerabilities
RCE w F5 BIG-IP APM poprzez złośliwy ruch sieciowy (stack buffer overflow)
F5 BIG-IP: Obejście uwierzytelnienia i zdalne wykonanie poleceń (RCE)
F5 BIG-IP: Pominięcie uwierzytelnienia iControl REST (RCE)
F5 BIG-IP/BIG-IQ iControl REST — nieuwierzytelniony RCE
F5 BIG-IP TMUI — krytyczny RCE przez path traversal (CVE-2020-5902)