{"api_version":"v1","generated_at":"2026-10-09T07:55:00+00:00","product":{"cve_count":1,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-f5-big-ip-traffic-management-microkernel-084756ac6bb5","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"BIG-IP Traffic Management Microkernel","next_cursor":null,"observations":[{"affected":"BIG-IP: 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3","affected_versions_present":true,"cve_id":"CVE-2021-22991","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-22991","fixed":"The Cyber Centre recommends organizations review all impacted F5 appliances and virtual deployments and patch to one of the below recommended versions. [ 1 ] BIG-IP: Versions 16.0.0 to 16.0.1 should be upgraded to 16.0.1.1 Versions 15.1.0 to 15.1.2 should be upgraded to 15.1.2.1 Versions 14.1.0 to 14.1.3.1 should be upgraded to 14.1.4 Versions 13.1.0 to 13.1.3.5 should be upgraded to 13.1.3.6 Versions 12.1.0 to 12.1.5.2 should be upgraded to 12.1.5.3 Versions 11.6.1 to 11.6.5.2 should be upgraded to 11.6.5.3 BIG-IQ: Version 8.0.0 is unaffected Versions 7.1.0 to 7.1.0.2 should be upgraded to 8.0.0 Versions 7.0.0 to 7.0.0.1 should be upgraded to 7.1.0.3 Versions 6.0.0 to 6.1.0 should be upgraded to 7.0.0.2 F5 indicates that if a fixed version has not been identified for a branch used by an organization then no update is available. F5 recommends that organizations upgrade to a version with an available patch. Organizations may use the F5 platform matrix to determine compatible software versions for their F5 platform. [ 1 ] While the Cyber Centre strongly encourages patching as soon as possible, administrators should consider applying the mitigations described in the F5 KB articles if patching is not immediately possible. See the [ 4 ] and [ 5 ] for more details. In summary: Block iControl REST access through the self IP address. Block iControl REST access through the management interface. Block Configuration utility access through self IP addresses. Block Configuration utility access through the management interface. Patching as described in this section also fixes the buffer overflow vulnerabilities described in the previous section. There are no mitigations against CVE-2021-22991 other than patching, while for CVE-2021-22992 F5 has provided an iRule mitigation. [ 9 ] In all cases, the Cyber Centre and F5 recommend patching as the primary mitigation.","last_modified":"2025-10-21T23:25:50.646Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/vulnerabilities-impacting-f5-big-ip-and-big-iq","primary_source":"","published":"2021-03-31T17:23:14.000Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"F5"}}
