CVE-2013-6016
published 2013-10-26CVE-2013-6016: The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, APM, ASM, Edge Gateway, GTM, Link Controller, and WOM 10.0.0 through 10.2.2 and 11.0.0; Analytics…
PriorityP339high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.75%
84.5th percentile
The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, APM, ASM, Edge Gateway, GTM, Link Controller, and WOM 10.0.0 through 10.2.2 and 11.0.0; Analytics 11.0.0; PSM 9.4.0 through 9.4.8, 10.0.0 through 10.2.4, and 11.0.0 through 11.4.1; and WebAccelerator 9.4.0 through 9.4.8, 10.0.0 through 10.2.4, and 11.0.0 through 11.3.0 might change a TCP connection to the ESTABLISHED state before receiving the ACK packet, which allows remote attackers to cause a denial of service (SIGFPE or assertion failure and TMM restart) via unspecified vectors.
Affected
86 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_global_traffic_manager | — | — |
| f5 | big-ip_link_controller | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/55378http://support.f5.com/kb/en-us/solutions/public/13000/200/sol13233.htmlhttp://www.securitytracker.com/id/1029220https://exchange.xforce.ibmcloud.com/vulnerabilities/88166http://secunia.com/advisories/55378http://support.f5.com/kb/en-us/solutions/public/13000/200/sol13233.htmlhttp://www.securitytracker.com/id/1029220https://exchange.xforce.ibmcloud.com/vulnerabilities/88166
2013-10-26
Published