CVE-2021-22999 is a denial-of-service vulnerability affecting F5 BIG-IP systems running versions 15.0.x before 15.1.0 and 14.1.x before 14.1.4. It occurs when the BIG-IP system, acting as a proxy between HTTP/2 clients and HTTP/1.x servers, fails to properly close streams if a slow client prematurely terminates a connection. This can lead to the indefinite retention of unclosed streams, consuming resources and potentially causing a denial of service. The vulnerability has a CVSS score of 7.5 (HIGH), indicating it can be exploited remotely with low complexity to achieve high availability impact. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 14.1.0, < 14.1.4CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* | ||
>= 15.0.0, < 15.1.0CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* | ||
>= 14.1.0, < 14.1.4CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* | ||
>= 15.0.0, < 15.1.0CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:* | ||
>= 14.1.0, < 14.1.4CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.