CVE-2017-6134
medium
CVSS v3
6.5
CVSS v2
3.3
VIR risk
6.5
Description
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0, 12.1.0 - 12.1.2 and 11.5.1 - 11.6.1, an undisclosed sequence of packets, sourced from an adjacent network may cause TMM to crash.
Predictions
Exploit likelihood
65%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: f5sirt@f5.com — https://support.f5.com/csp/article/K37404773
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| f5 | big-ip_local_traffic_manager | {"startIncluding":"11.5.1","endIncluding":"11.6.1"} | |
| f5 | big-ip_local_traffic_manager | 13.0.0 | |
| f5 | big-ip_application_acceleration_manager | {"startIncluding":"11.5.1","endIncluding":"11.6.1"} | |
| f5 | big-ip_application_acceleration_manager | 13.0.0 | |
| f5 | big-ip_advanced_firewall_manager | {"startIncluding":"11.5.1","endIncluding":"11.6.1"} | |
| f5 | big-ip_advanced_firewall_manager | 13.0.0 | |
| f5 | big-ip_analytics | {"startIncluding":"11.5.1","endIncluding":"11.6.1"} | |
| f5 | big-ip_analytics | 13.0.0 | |
| f5 | big-ip_access_policy_manager | {"startIncluding":"11.5.1","endIncluding":"11.6.1"} | |
| f5 | big-ip_access_policy_manager | 13.0.0 | |
| f5 | big-ip_application_security_manager | {"startIncluding":"11.5.1","endIncluding":"11.6.1"} | |
| f5 | big-ip_application_security_manager | 13.0.0 | |
| f5 | big-ip_dns | {"startIncluding":"11.5.1","endIncluding":"11.6.1"} | |
| f5 | big-ip_dns | 13.0.0 | |
| f5 | big-ip_global_traffic_manager | {"startIncluding":"11.5.1","endIncluding":"11.6.1"} | |
| f5 | big-ip_global_traffic_manager | 13.0.0 | |
| f5 | big-ip_link_controller | {"startIncluding":"11.5.1","endIncluding":"11.6.1"} | |
| f5 | big-ip_link_controller | 13.0.0 | |
| f5 | big-ip_policy_enforcement_manager | {"startIncluding":"11.5.1","endIncluding":"11.6.1"} | |
| f5 | big-ip_policy_enforcement_manager | 13.0.0 | |
| f5 | big-ip_websafe | {"startIncluding":"11.5.1","endIncluding":"11.6.1"} | |
| f5 | big-ip_websafe | 13.0.0 | |
References
- http://www.securityfocus.com/bid/102466
- http://www.securitytracker.com/id/1040044
- http://www.securitytracker.com/id/1040045
- https://support.f5.com/csp/article/K37404773
- http://www.securityfocus.com/bid/102466
- http://www.securitytracker.com/id/1040044
- http://www.securitytracker.com/id/1040045
- https://support.f5.com/csp/article/K37404773
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.