CVE-2017-6159

Severity

43%

Complexity

86%

Confidentiality

48%

F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 are vulnerable to a denial of service attack when the MPTCP option is enabled on a virtual server. Data plane is vulnerable when using the MPTCP option of a TCP profile. There is no control plane exposure. An attacker may be able to disrupt services by causing TMM to restart hence temporarily failing to process traffic.

F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 are vulnerable to a denial of service attack when the MPTCP option is enabled on a virtual server. Data plane is vulnerable when using the MPTCP option of a TCP profile. There is no control plane exposure. An attacker may be able to disrupt services by causing TMM to restart hence temporarily failing to process traffic.

CVSS 3.0 Base Score 5.9. CVSS Attack Vector: network. CVSS Attack Complexity: high. CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS 2.0 Base Score 4.3. CVSS Attack Vector: network. CVSS Attack Complexity: medium. CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).

Overview

Type

F5

First reported 7 years ago

2017-10-27 14:29:00

Last updated 5 years ago

2019-10-03 00:03:00

Affected Software

F5 BIG-IP Local Traffic Manager 11.6.0

11.6.0

F5 Networks BIG-IP Local Traffic Manager 11.6.1

11.6.1

F5 BIG-IP Local Traffic Manager (LTM) 12.0.0

12.0.0

F5 BIG-IP Local Traffic Manager (LTM) 12.1.0

12.1.0

F5 BIG-IP Local Traffic Manager (LTM) 12.1.1

12.1.1

F5 Big-IP Local Traffic Manager (LTM) 12.1.2

12.1.2

F5 BIG-IP Application Acceleration Manager 11.6.0

11.6.0

F5 Networks BIG-IP Application Acceleration Manager 11.6.1

11.6.1

F5 BIG-IP Application Acceleration Manager (AAM) 12.0.0

12.0.0

F5 Networks BIG-IP Application Acceleration Manager 12.1.0

12.1.0

F5 BIG-IP Application Acceleration Manager (AAM) 12.1.1

12.1.1

F5 Big-IP Application Acceleration Manager (AAM) 12.1.2

12.1.2

F5 BIG-IP Advanced Firewall Manager 11.6.0

11.6.0

F5 Networks BIG-IP Advanced Firewall Manager 11.6.1

11.6.1

F5 BIG-IP Advanced Firewall Manager (APM) 12.0.0

12.0.0

F5 BIG-IP Advanced Firewall Manager (AFM) 12.1.0

12.1.0

F5 BIG-IP Advanced Firewall Manager (AFM) 12.1.1

12.1.1

F5 Big-IP Advanced Firewall Manager (AFM) 12.1.2

12.1.2

F5 Big-IP Access Policy Manager (APM) 11.6.0

11.6.0

F5 Networks BIG-IP Access Policy Manager 11.6.1

11.6.1

F5 BIG-IP Access Policy Manager (APM) 12.0.0

12.0.0

F5 BIG-IP Access Policy Manager (APM) 12.1.0

12.1.0

F5 BIG-IP Access Policy Manager (APM) 12.1.1

12.1.1

F5 Big-IP Access Policy Manager (APM) 12.1.2

12.1.2

F5 BIG-IP Application Security Manager 11.6.0

11.6.0

F5 Networks BIG-IP Application Security Manager 11.6.1

11.6.1

F5 BIG-IP Application Security Manager (ASM) 12.0.0

12.0.0

F5 BIG-IP Application Security Manager (ASM) 12.1.0

12.1.0

F5 BIG-IP Application Security Manager (ASM) 12.1.1

12.1.1

F5 Big-IP Application Security Manager (ASM) 12.1.2

12.1.2

F5 BIG-IP Link Controller 11.6.0

11.6.0

F5 Networks BIG-IP Link Controller 11.6.1

11.6.1

F5 BIG-IP Link Controller 12.0.0

12.0.0

F5 BIG-IP Link Controller 12.1.0

12.1.0

F5 BIG-IP Link Controller 12.1.1

12.1.1

F5 Big-IP Link Controller 12.1.2

12.1.2

F5 BIG-IP Policy Enforcement Manager 11.6.0

11.6.0

F5 Networks BIG-IP Policy Enforcement Manager 11.6.1

11.6.1

F5 BIG-IP Policy Enforcement Manager (PEM) 12.0.0

12.0.0

F5 BIG-IP Policy Enforcement Manager (PEM) 12.1.0

12.1.0

F5 BIG-IP Policy Enforcement Manager (PEM) 12.1.1

12.1.1

F5 Big-IP Policy Enforcement Manager (PEM) 12.1.2

12.1.2

F5 Networks BIG-IP Websafe 1.0.0

1.0.0

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.