← Back to browse · API

CVE-2021-22991

Severity
CRITICAL
CVSS
9.8
EPSS
0.61064
Risk score
85.57
CISA KEV
Yes
PoC
No
Published
2022-01-18
Modified
2022-01-18
First seen
2026-08-07
Aliases
EUVD-2021-10109, GHSA-6W8R-PJM3-Q7X7
Products
F5:BIG-IP 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, F5:BIG-IP Traffic Management Microkernel
Sources
euvd EUVD-2021-10109
cisa.gov CVE-2021-22991

Description

The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.

References