BIG-IP AFM Device Vulnerable to Termination Due to Undisclosed Queries
CVE-2024-21763
7.5HIGH
Summary
A vulnerability in the BIG-IP AFM Device occurs when the DoS profile is configured with an NXDOMAIN attack vector and bad actor detection is enabled. This configuration can lead to improper handling of undisclosed DNS queries, potentially causing the Traffic Management Microkernel (TMM) to terminate unexpectedly. Organizations using affected versions should review their configurations to mitigate risks associated with this issue.
Affected Version(s)
BIG-IP 17.1.0 < 17.1.1
BIG-IP 16.1.0 < 16.1.4
BIG-IP 15.1.0 < 15.1.10
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
F5