← Vulnerability feed

Vulnerability record · CVE-2021-22991 · published 31 March 2021

CVE-2021-22991: F5 BIG-IP TMM URI normalization buffer overflow

F5 · Big Ip Access Policy Manager

F5 BIG-IP's Traffic Management Microkernel (TMM) mishandles URI normalization for undisclosed requests to a virtual server, triggering a buffer overflow. The flaw affects many BIG-IP modules across versions 12.1.x through 16.0.x and can cause denial of service, with the vendor noting theoretical URL access control bypass or remote code execution.

9.8 CVSS 3.1 Critical CISA KEV since 18 Jan 2022 EPSS 61% · top 0.9% CWE-119 · Memory buffer overflow
9.8CVSS 3.1 base score, v2 6.8
61%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
14Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, CISA KEV listing and high EPSS probability indicate an actively exploited, remotely reachable flaw with severe availability and potential confidentiality and integrity impact.

What it is

F5 BIG-IP's Traffic Management Microkernel (TMM) mishandles URI normalization for undisclosed requests to a virtual server, triggering a buffer overflow. The flaw affects many BIG-IP modules across versions 12.1.x through 16.0.x and can cause denial of service, with the vendor noting theoretical URL access control bypass or remote code execution.

Impact

An unauthenticated remote attacker can crash or disrupt the TMM process, causing denial of service on the virtual server. In certain situations the vendor states it may theoretically allow bypass of URL-based access control or remote code execution.

Attack surface

Reached over the network by sending crafted requests to a BIG-IP virtual server; the CVSS vector shows no privileges or user interaction required. No authentication is needed per the AV:N/AC:L/PR:N/UI:N vector.

Exploitation

Listed in CISA KEV since 2022-01-18 with a 2022-02-01 remediation due date, and EPSS 30-day probability is 0.61 (99th percentile), indicating observed exploitation activity. No ransomware campaign use is recorded.

What to do

  • Apply the F5 vendor updates for the affected BIG-IP versions (16.0.1.1, 15.1.2.1, 14.1.4, 13.1.3.6, 12.1.5.3 or later) as directed in F5 article K56715231.
  • Upgrade or migrate any BIG-IP software that has reached End of Software Development, since those versions are not evaluated or fixed.
  • Restrict management and virtual server exposure to trusted networks where operationally feasible to reduce reachable attack surface.
  • Monitor F5 security advisories and CISA KEV for updated guidance and re-check exposure after patching.

Detection

  • Monitor TMM process crashes, restarts or core dumps on BIG-IP systems and correlate with inbound request patterns.
  • Inspect BIG-IP and upstream logs for malformed or unusual URI normalization requests hitting virtual servers.
  • Alert on availability drops or traffic anomalies for virtual servers consistent with a TMM buffer overflow DoS.
  • Track CISA KEV and F5 advisory status to confirm patched versions across the fleet.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-22991 to the Known Exploited Vulnerabilities catalog on 18 January 2022 as "F5 BIG-IP Traffic Management Microkernel Buffer Overflow". Required action: Apply updates per vendor instructions. Federal deadline 1 February 2022.

Affected products

14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22991 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-46747F5 BIG-IP configuration utility authentication bypass allows command executionUndisclosed requests can bypass authentication in the BIG-IP configuration utility, letting a network-positioned attacker execute arbitrary system co…KEVEPSS 97%analysed9.8CVE-2022-1388F5 BIG-IP iControl REST authentication bypassUndisclosed requests to the iControl REST interface on multiple F5 BIG-IP modules can bypass authentication, allowing an unauthenticated remote attac…KEVEPSS 100%analysed9.8CVE-2021-22986F5 BIG-IP iControl REST unauthenticated remote command executionThe iControl REST interface on multiple F5 BIG-IP and BIG-IQ versions exposes an unauthenticated remote command execution flaw, tracked as CWE-918 se…KEVEPSS 100%analysed9.8CVE-2020-5902F5 BIG-IP TMUI path traversal leading to remote code executionThe F5 BIG-IP Traffic Management User Interface (TMUI, also called the Configuration utility) contains a path traversal flaw (CWE-22) in undisclosed …KEVEPSS 100%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed9.3CVE-2026-94127F5 big-ip access policy manager heap-based buffer overflow vulnerabilityWhen a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution…KEVEPSS 2.2%9.3CVE-2025-53521F5 BIG-IP APM stack buffer overflow allows remote code executionA stack-based buffer overflow (CWE-121) exists in F5 BIG-IP Access Policy Manager when an APM access policy is configured on a virtual server. Specif…KEVEPSS 2.3%analysed

Source: NIST National Vulnerability Database (record CVE-2021-22991), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.