Vulnerability Name:

CVE-2021-23007 (CCN-199209)

Assigned:2021-03-26
Published:2021-03-26
Updated:2021-04-06
Summary:On BIG-IP versions 14.1.4 and 16.0.1.1, when the Traffic Management Microkernel (TMM) process handles certain undisclosed traffic, it may start dropping all fragmented IP traffic.
Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
CVSS v3 Severity:5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2021-23007

Source: XF
Type: UNKNOWN
f5-cve202123007-dos(199209)

Source: CCN
Type: F5 Security Advisory K37451543
TMM vulnerability CVE-2021-23007

Source: MISC
Type: Exploit, Patch, Vendor Advisory
https://support.f5.com/csp/article/K37451543

Vulnerable Configuration:Configuration 1:
  • cpe:/a:f5:big-ip_access_policy_manager:14.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_access_policy_manager:16.0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_advanced_firewall_manager:14.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_advanced_firewall_manager:16.0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_advanced_web_application_firewall:14.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_advanced_web_application_firewall:16.0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_analytics:14.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_analytics:16.0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_application_acceleration_manager:14.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_application_acceleration_manager:16.0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_application_security_manager:14.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_application_security_manager:16.0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_ddos_hybrid_defender:14.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_ddos_hybrid_defender:16.0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_domain_name_system:14.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_domain_name_system:16.0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_edge_gateway:14.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_edge_gateway:16.0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_fraud_protection_service:14.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_fraud_protection_service:16.0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_global_traffic_manager:14.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_global_traffic_manager:16.0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_link_controller:14.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_link_controller:16.0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_local_traffic_manager:14.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_local_traffic_manager:16.0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_policy_enforcement_manager:14.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_policy_enforcement_manager:16.0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_ssl_orchestrator:14.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_ssl_orchestrator:16.0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_webaccelerator:14.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:f5:big-ip_webaccelerator:16.0.1.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    f5 big-ip access policy manager 14.1.4
    f5 big-ip access policy manager 16.0.1.1
    f5 big-ip advanced firewall manager 14.1.4
    f5 big-ip advanced firewall manager 16.0.1.1
    f5 big-ip advanced web application firewall 14.1.4
    f5 big-ip advanced web application firewall 16.0.1.1
    f5 big-ip analytics 14.1.4
    f5 big-ip analytics 16.0.1.1
    f5 big-ip application acceleration manager 14.1.4
    f5 big-ip application acceleration manager 16.0.1.1
    f5 big-ip application security manager 14.1.4
    f5 big-ip application security manager 16.0.1.1
    f5 big-ip ddos hybrid defender 14.1.4
    f5 big-ip ddos hybrid defender 16.0.1.1
    f5 big-ip domain name system 14.1.4
    f5 big-ip domain name system 16.0.1.1
    f5 big-ip edge gateway 14.1.4
    f5 big-ip edge gateway 16.0.1.1
    f5 big-ip fraud protection service 14.1.4
    f5 big-ip fraud protection service 16.0.1.1
    f5 big-ip global traffic manager 14.1.4
    f5 big-ip global traffic manager 16.0.1.1
    f5 big-ip link controller 14.1.4
    f5 big-ip link controller 16.0.1.1
    f5 big-ip local traffic manager 14.1.4
    f5 big-ip local traffic manager 16.0.1.1
    f5 big-ip policy enforcement manager 14.1.4
    f5 big-ip policy enforcement manager 16.0.1.1
    f5 big-ip ssl orchestrator 14.1.4
    f5 big-ip ssl orchestrator 16.0.1.1
    f5 big-ip webaccelerator 14.1.4
    f5 big-ip webaccelerator 16.0.1.1