LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-22991: F5 BIG-IP Traffic Management Microkernel Buffer Overflow

RBRecent Breaches Vulnerability Intelligence·Jan 18, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 1, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-22991 to its Known Exploited Vulnerabilities catalog on Jan 18, 2022, with a federal patch deadline of Feb 1, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.

CVE-2021-22991 is a buffer overflow in the Traffic Management Microkernel of F5 BIG-IP, specifically tied to the ASM Risk Engine. It can allow an attacker to bypass URL-based access controls. For teams running BIG-IP as a reverse proxy, load balancer, or application security layer, that bypass undermines a core control and can expose backends that were meant to stay restricted. Confirm exact scope and fixed releases against the vendor advisory.

CISA lists the required action as applying updates per vendor instructions. Public detail on ransomware use is not documented for this CVE; treat it as a serious access-control failure that needs prompt inventory and patching.

How it works

The weakness is classified as CWE-119 (improper restriction of operations within the bounds of a memory buffer). In plain terms, the Traffic Management Microkernel mishandles certain input in a way that overflows a buffer. Per the CISA summary, that condition in the BIG-IP ASM Risk Engine can be abused to bypass URL-based access controls.

An attacker who can reach the vulnerable component sends crafted traffic that triggers the overflow. Successful abuse lets them reach URLs or paths that the ASM policy was supposed to block. Exact request shape, preconditions, and whether remote code execution is possible are not specified in the provided facts; defenders should treat the outcome as unauthorized access past URL controls and verify full impact in the vendor advisory. No exploit mechanics beyond that summary should be assumed.

Am I affected? How to find it in your systems

F5 BIG-IP appliances and virtual editions commonly sit at the edge or in the DMZ, terminating TLS, load-balancing, and enforcing ASM (Application Security Manager) policies. The vulnerable piece is the Traffic Management Microkernel in the context of the ASM Risk Engine.

How to remediate

Patch first. Apply the updates F5 published for this issue, following the vendor’s instructions exactly (CISA’s required action). Schedule maintenance windows for production pairs, validate the fixed build in a lab or staging traffic group, then roll forward with your normal BIG-IP upgrade process (image install, reboot or failover as required, config sync).

If you can't patch immediately

Reduce exposure until the vendor update can be applied.

If your data may have been exposed

Actively exploited access-control flaws on edge devices can lead to unauthorized access and follow-on compromise of applications behind the BIG-IP. If you find evidence of bypass or cannot rule out exploitation, follow your incident-response process: isolate affected traffic groups if needed, preserve logs, credential-reset, and hunt for lateral movement on backends. Known ransomware use is not documented for this CVE, but treat any confirmed breach seriously. You can run a free exposure scan of your email addresses against known breach datasets to see whether associated accounts appear in prior dumps, then force password changes and MFA where relevant.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedF5 · BIG-IP Traffic Management Microkernel
WeaknessCWE-119
Added to CISA KEVJan 18, 2022
Federal patch deadlineFeb 1, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities