← Vulnerability feed

Vulnerability record · CVE-2021-22992 · published 31 March 2021

CVE-2021-22992: F5 BIG-IP ASM/Advanced WAF Login Page Buffer Overflow

F5 · Big Ip Access Policy Manager

A buffer overflow exists in F5 BIG-IP Advanced WAF/BIG-IP ASM virtual servers that have a Login Page configured in their policy. A malicious HTTP response can trigger the overflow, causing a denial of service and, in certain situations, remote code execution leading to complete system compromise.

9.8 CVSS 3.1 Critical EPSS 73% · top 0.6% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score, v2 9.3
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
14Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, a malicious HTTP response to an Advanced WAF/BIG-IP ASM virtual server with Login Page configured in its policy may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may allow remote code execution (RCE), leading to complete system compromise. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication or user interaction, potential RCE, and very high EPSS make this a critical patching priority.

What it is

A buffer overflow exists in F5 BIG-IP Advanced WAF/BIG-IP ASM virtual servers that have a Login Page configured in their policy. A malicious HTTP response can trigger the overflow, causing a denial of service and, in certain situations, remote code execution leading to complete system compromise.

Impact

An attacker can crash the affected virtual server (DoS) and, under certain conditions, execute arbitrary code, resulting in full compromise of the BIG-IP system.

Attack surface

The flaw is reached over the network via a malicious HTTP response to a virtual server with a Login Page configured in its policy. The CVSS vector indicates no authentication and no user interaction are required.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high (0.72711, 99.4th percentile), indicating elevated likelihood of exploitation activity; the only references are vendor advisories, with no public exploit tags.

What to do

  • Upgrade to the fixed BIG-IP versions listed in the F5 advisory (16.0.1.1, 15.1.2.1, 14.1.4, 13.1.3.6, 12.1.5.3, 11.6.5.3 or later) as the primary action.
  • If immediate patching is not possible, remove or disable the Login Page configuration from affected Advanced WAF/ASM policies where operationally feasible.
  • Restrict network access to affected virtual servers to trusted sources only.
  • Monitor F5 security advisories for updated guidance and any workarounds.
  • Plan migration off end-of-software-development BIG-IP branches that are not evaluated for fixes.

Detection

  • Monitor BIG-IP ASM/WAF logs and system logs for crashes, restarts, or unexpected process terminations on virtual servers with Login Page policies.
  • Inspect HTTP response traffic to affected virtual servers for anomalous or malformed responses that could trigger the overflow.
  • Alert on unexpected BIG-IP service restarts or failover events that correlate with HTTP response handling.
  • Review F5 iHealth or BIG-IP diagnostics for buffer overflow or memory corruption indicators.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22992 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-46747F5 BIG-IP configuration utility authentication bypass allows command executionUndisclosed requests can bypass authentication in the BIG-IP configuration utility, letting a network-positioned attacker execute arbitrary system co…KEVEPSS 97%analysed9.8CVE-2022-1388F5 BIG-IP iControl REST authentication bypassUndisclosed requests to the iControl REST interface on multiple F5 BIG-IP modules can bypass authentication, allowing an unauthenticated remote attac…KEVEPSS 100%analysed9.8CVE-2021-22991F5 BIG-IP TMM URI normalization buffer overflowF5 BIG-IP's Traffic Management Microkernel (TMM) mishandles URI normalization for undisclosed requests to a virtual server, triggering a buffer overf…KEVEPSS 61%analysed9.8CVE-2021-22986F5 BIG-IP iControl REST unauthenticated remote command executionThe iControl REST interface on multiple F5 BIG-IP and BIG-IQ versions exposes an unauthenticated remote command execution flaw, tracked as CWE-918 se…KEVEPSS 100%analysed9.8CVE-2020-5902F5 BIG-IP TMUI path traversal leading to remote code executionThe F5 BIG-IP Traffic Management User Interface (TMUI, also called the Configuration utility) contains a path traversal flaw (CWE-22) in undisclosed …KEVEPSS 100%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed9.3CVE-2026-94127F5 big-ip access policy manager heap-based buffer overflow vulnerabilityWhen a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution…KEVEPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2021-22992), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.