Vulnerability record · CVE-2021-22991 · published 31 March 2021
CVE-2021-22991: F5 BIG-IP TMM URI normalization buffer overflow
F5 · Big Ip Access Policy Manager
F5 BIG-IP's Traffic Management Microkernel (TMM) mishandles URI normalization for undisclosed requests to a virtual server, triggering a buffer overflow. The flaw affects many BIG-IP modules across versions 12.1.x through 16.0.x and can cause denial of service, with the vendor noting theoretical URL access control bypass or remote code execution.
Description
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, CISA KEV listing and high EPSS probability indicate an actively exploited, remotely reachable flaw with severe availability and potential confidentiality and integrity impact.
What it is
F5 BIG-IP's Traffic Management Microkernel (TMM) mishandles URI normalization for undisclosed requests to a virtual server, triggering a buffer overflow. The flaw affects many BIG-IP modules across versions 12.1.x through 16.0.x and can cause denial of service, with the vendor noting theoretical URL access control bypass or remote code execution.
Impact
An unauthenticated remote attacker can crash or disrupt the TMM process, causing denial of service on the virtual server. In certain situations the vendor states it may theoretically allow bypass of URL-based access control or remote code execution.
Attack surface
Reached over the network by sending crafted requests to a BIG-IP virtual server; the CVSS vector shows no privileges or user interaction required. No authentication is needed per the AV:N/AC:L/PR:N/UI:N vector.
Exploitation
Listed in CISA KEV since 2022-01-18 with a 2022-02-01 remediation due date, and EPSS 30-day probability is 0.61 (99th percentile), indicating observed exploitation activity. No ransomware campaign use is recorded.
What to do
- Apply the F5 vendor updates for the affected BIG-IP versions (16.0.1.1, 15.1.2.1, 14.1.4, 13.1.3.6, 12.1.5.3 or later) as directed in F5 article K56715231.
- Upgrade or migrate any BIG-IP software that has reached End of Software Development, since those versions are not evaluated or fixed.
- Restrict management and virtual server exposure to trusted networks where operationally feasible to reduce reachable attack surface.
- Monitor F5 security advisories and CISA KEV for updated guidance and re-check exposure after patching.
Detection
- Monitor TMM process crashes, restarts or core dumps on BIG-IP systems and correlate with inbound request patterns.
- Inspect BIG-IP and upstream logs for malformed or unusual URI normalization requests hitting virtual servers.
- Alert on availability drops or traffic anomalies for virtual servers consistent with a TMM buffer overflow DoS.
- Track CISA KEV and F5 advisory status to confirm patched versions across the fleet.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-22991 to the Known Exploited Vulnerabilities catalog on 18 January 2022 as "F5 BIG-IP Traffic Management Microkernel Buffer Overflow". Required action: Apply updates per vendor instructions. Federal deadline 1 February 2022.
Affected products
14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.f5.com/csp/article/K56715231 | Vendor Advisory |
| https://support.f5.com/csp/article/K56715231 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22991 | US Government Resource |
Track CVE-2021-22991 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-22991), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.