#VU50620 Resource exhaustion in BIG-IP Advanced WAF and BIG-IP ASM - CVE-2021-22976
Published: February 11, 2021
BIG-IP Advanced WAF
BIG-IP ASM
F5 Networks
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when processing WebSocket requests with JSON payloads. A remote attacker can send a huge amount of parameters in a request, trigger resource exhaustion and perform a denial of service (DoS) attack.