CVE Vulnerabilities

CVE-2017-6159

Published: Oct 27, 2017 | Modified: Oct 03, 2019
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 are vulnerable to a denial of service attack when the MPTCP option is enabled on a virtual server. Data plane is vulnerable when using the MPTCP option of a TCP profile. There is no control plane exposure. An attacker may be able to disrupt services by causing TMM to restart hence temporarily failing to process traffic.

Affected Software

Name Vendor Start Version End Version
Big-ip_local_traffic_manager F5 11.6.0 (including) 11.6.0 (including)
Big-ip_local_traffic_manager F5 11.6.1 (including) 11.6.1 (including)
Big-ip_local_traffic_manager F5 12.0.0 (including) 12.0.0 (including)
Big-ip_local_traffic_manager F5 12.1.0 (including) 12.1.0 (including)
Big-ip_local_traffic_manager F5 12.1.1 (including) 12.1.1 (including)
Big-ip_local_traffic_manager F5 12.1.2 (including) 12.1.2 (including)

References