Home / Early Warning / Vulnerabilidades / CVE-2021-23011

CVE-2021-23011

Type: 
Uncontrolled Resource Consumption ('Resource Exhaustion')
Severity: 
Medium
Publication date: 
05/10/2021
Last modified: 
05/24/2021
Description
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5.3, when the BIG-IP system is buffering packet fragments for reassembly, the Traffic Management Microkernel (TMM) may consume an excessive amount of resources, eventually leading to a restart and failover event. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Impact
Access Vector: Through network
Access Complexity: Low
Authentication: Not required to exploit
Impact Type: No impact on system integrity + No impact on system confidentiality + Partially affects on system availability
Vulnerable software and versions
  • cpe:2.3:a:f5:big-ip_ssl_orchestrator:*:*:*:*:*:*:*:*
  • cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
  • cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
  • cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
  • cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
  • cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*
  • cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*
  • cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*
  • cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
  • cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
  • cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
  • cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*
  • cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
  • cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
To consult the complete list of products and versions see this page
References to Advisories, Solutions, and Tools
Explanation of fields