DoS Vulnerability in F5 BIG-IP Systems Affecting Specific Versions
CVE-2017-6150
7.5HIGH
Key Information:
- Vendor
- F5
- Vendor
- CVE Published:
- 1 March 2018
Summary
A vulnerability exists in F5 BIG-IP systems versions 13.0.0 and 12.1.0 to 12.1.3.1 that may allow denial of service. When using FastL4 profiles and with the Reassemble IP Fragments option disabled (default setting), certain large fragmented packets can unintentionally restart the Traffic Management Microkernel (TMM), potentially leading to service interruptions and degraded performance.
Affected Version(s)
BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, WebSafe 13.0.0
BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, WebSafe 12.1.0 - 12.1.3.1
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved