CVE-2021-23036 describes a denial-of-service vulnerability affecting F5 BIG-IP ASM and DataSafe modules on version 16.0.x before 16.0.1.2. Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate, leading to system unavailability. This vulnerability has a CVSS score of 7.5 (High), indicating a network-exploitable issue with low attack complexity and high impact on availability, requiring no user interaction or privileges. While there is no evidence of active exploitation, public exploit code, or Metasploit modules, the vulnerability has garnered significant media attention and community discussion, suggesting awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.0.0, <= 16.0.1CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:* | ||
>= 16.0.0, <= 16.0.1CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:* | ||
>= 16.0.0, <= 16.0.1CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_datasafe:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.