Traffic Management Microkernel Restart Vulnerability in F5 BIG-IP Systems
CVE-2016-9247

5.9MEDIUM

What is CVE-2016-9247?

In certain scenarios involving F5 BIG-IP systems, a specific sequence of packets sent to a virtual server configured with a FastL4 profile alongside a TCP analytics profile may inadvertently trigger a restart of the Traffic Management Microkernel (TMM). This behavior can disrupt service and impact the performance of network traffic management, necessitating awareness and potential mitigation strategies for organizations utilizing this technology.

Affected Version(s)

F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, WebSafe 12.1.0 - 12.1.1

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.