Resource exhaustion in BIG-IP ASM and BIG-IP Advanced WAF - CVE-2021-22976
Published: February 11, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when processing WebSocket requests with JSON payloads. A remote attacker can send a huge amount of parameters in a request, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
BIG-IP Advanced WAF
How to mitigate CVE-2021-22976
BIG-IP Advanced WAF - addressed in versions 13.1.3.6, 14.1.3.1, 15.1.2, 16.0.1.1