Remote Service Disruption Vulnerability in F5 BIG-IP by F5 Networks
CVE-2016-7468
5.9MEDIUM
What is CVE-2016-7468?
An unauthenticated remote attacker can exploit a vulnerability in F5 BIG-IP devices (versions 11.4.1 to 11.5.4) by sending specially crafted network traffic. This issue predominantly affects virtual servers linked to TCP profiles when the tm.tcpprogressive database variable is configured to 'enabled', deviating from its default setting of 'negotiate'. Exploitation could lead to traffic disruption or potentially trigger a failover to another device within the group, impacting service continuity.
Affected Version(s)
F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, PEM, PSM, 11.4.1 - 11.5.4