Vulnerability record · CVE-2021-22992 · published 31 March 2021
CVE-2021-22992: F5 BIG-IP ASM/Advanced WAF Login Page Buffer Overflow
F5 · Big Ip Access Policy Manager
A buffer overflow exists in F5 BIG-IP Advanced WAF/BIG-IP ASM virtual servers that have a Login Page configured in their policy. A malicious HTTP response can trigger the overflow, causing a denial of service and, in certain situations, remote code execution leading to complete system compromise.
Description
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, a malicious HTTP response to an Advanced WAF/BIG-IP ASM virtual server with Login Page configured in its policy may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may allow remote code execution (RCE), leading to complete system compromise. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or user interaction, potential RCE, and very high EPSS make this a critical patching priority.
What it is
A buffer overflow exists in F5 BIG-IP Advanced WAF/BIG-IP ASM virtual servers that have a Login Page configured in their policy. A malicious HTTP response can trigger the overflow, causing a denial of service and, in certain situations, remote code execution leading to complete system compromise.
Impact
An attacker can crash the affected virtual server (DoS) and, under certain conditions, execute arbitrary code, resulting in full compromise of the BIG-IP system.
Attack surface
The flaw is reached over the network via a malicious HTTP response to a virtual server with a Login Page configured in its policy. The CVSS vector indicates no authentication and no user interaction are required.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.72711, 99.4th percentile), indicating elevated likelihood of exploitation activity; the only references are vendor advisories, with no public exploit tags.
What to do
- Upgrade to the fixed BIG-IP versions listed in the F5 advisory (16.0.1.1, 15.1.2.1, 14.1.4, 13.1.3.6, 12.1.5.3, 11.6.5.3 or later) as the primary action.
- If immediate patching is not possible, remove or disable the Login Page configuration from affected Advanced WAF/ASM policies where operationally feasible.
- Restrict network access to affected virtual servers to trusted sources only.
- Monitor F5 security advisories for updated guidance and any workarounds.
- Plan migration off end-of-software-development BIG-IP branches that are not evaluated for fixes.
Detection
- Monitor BIG-IP ASM/WAF logs and system logs for crashes, restarts, or unexpected process terminations on virtual servers with Login Page policies.
- Inspect HTTP response traffic to affected virtual servers for anomalous or malformed responses that could trigger the overflow.
- Alert on unexpected BIG-IP service restarts or failover events that correlate with HTTP response handling.
- Review F5 iHealth or BIG-IP diagnostics for buffer overflow or memory corruption indicators.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.f5.com/csp/article/K52510511 | Vendor Advisory |
| https://support.f5.com/csp/article/K52510511 | Vendor Advisory |
Track CVE-2021-22992 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-22992), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.