QID 376078
Date Published: 2021-11-18
QID 376078: F5 BIG-IP Access Policy Manager (APM) Vulnerability (K32049501)
Under certain conditions, when processing VPN traffic with APM, TMM consumes excessive memory. A malicious, authenticated VPN user may abuse this to perform a DoS attack against the APM.CVE-2021-22985
Vulnerable Component: BIG-IP APM
Affected Versions:
16.0.0 - 16.0.1
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
The BIG-IP APM system may consume excessive memory and cause the Traffic Management Microkernel (TMM) to exit and restart. If you configured your BIG-IP APM system for high availability (HA), it may fail over to a standby system.
Solution
The vendor has released patch, for more information please visit: K32049501
Vendor References
- K32049501 -
support.f5.com/csp/article/K32049501
CVEs related to QID 376078
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K32049501 |
|