DoS Vulnerability in F5 BIG-IP Systems Affecting Specific Versions
CVE-2017-6150

7.5HIGH

Key Information:

Summary

A vulnerability exists in F5 BIG-IP systems versions 13.0.0 and 12.1.0 to 12.1.3.1 that may allow denial of service. When using FastL4 profiles and with the Reassemble IP Fragments option disabled (default setting), certain large fragmented packets can unintentionally restart the Traffic Management Microkernel (TMM), potentially leading to service interruptions and degraded performance.

Affected Version(s)

BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, WebSafe 13.0.0

BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, WebSafe 12.1.0 - 12.1.3.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.