ZeroHour

CVE-2017-6159

CVSS 3.0
5.9 medium
EPSS
2%p74
Published
()
Modified
Description

F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 are vulnerable to a denial of service attack when the MPTCP option is enabled on a virtual server. Data plane is vulnerable when using the MPTCP option of a TCP profile. There is no control plane exposure. An attacker may be able to disrupt services by causing TMM to restart hence temporarily failing to process traffic.

Vendors
f5
Products
big-ip local traffic manager, big-ip application acceleration manager, big-ip advanced firewall manager, big-ip access policy manager, big-ip application security manager, big-ip link controller, big-ip policy enforcement manager, big-ip websafe
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.