
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-22977 affects BIG-IP versions 16.0.0-16.0.1 and 14.1.2.4-14.1.3. The vulnerability involves cooperation between malicious HTTP client code and a malicious server that may cause TMM (Traffic Management Microkernel) to restart and generate a core file (MITRE CVE). The vulnerability was discovered and disclosed in early 2021, with the CVE being created on January 6, 2021.
The vulnerability has received a CVSS v3.1 score of 8.3 (HIGH) and CVSS v2.0 score of 5.1 (MEDIUM) (NVD). The vulnerability affects multiple BIG-IP modules including LTM, AAM, Advanced WAF, AFM, Analytics, APM, ASM, DDHD, DNS, FPS, GTM, Link Controller, PEM, and SSLO (CERT-FR).
When exploited, this vulnerability can cause the Traffic Management Microkernel (TMM) to restart and generate a core file, potentially leading to service disruption (MITRE CVE).
The vulnerability has been addressed in versions 14.1.3.1, 15.1.2.1, and 16.0.1.1 with the latest patches. Organizations running affected versions should upgrade to these patched versions (CERT-FR).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."