CVE-2017-6150

Severity
7.5HIGH
EPSS
0.6%
top 30.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 1
Latest updateMay 14

Description

Under certain conditions for F5 BIG-IP systems 13.0.0 or 12.1.0 - 12.1.3.1, using FastL4 profiles, when the Reassemble IP Fragments option is disabled (default), some specific large fragmented packets may restart the Traffic Management Microkernel (TMM).

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages10 packages

NVDf5/big-ip_local_traffic_manager12.1.012.1.3.1+1
NVDf5/big-ip_dns12.1.012.1.3.1+1
NVDf5/big-ip_websafe12.1.012.1.3.1+1
NVDf5/big-ip_analytics12.1.012.1.3.1+1
NVDf5/big-ip_link_controller12.1.012.1.3.1+1

🔴Vulnerability Details

2
GHSA
GHSA-cm64-prvx-8p5v: Under certain conditions for F5 BIG-IP systems 132022-05-14
CVEList
CVE-2017-6150: Under certain conditions for F5 BIG-IP systems 132018-03-01

📋Vendor Advisories

1
F5
CVE-2017-6150: Under certain conditions for F5 BIG-IP systems 132018-03-01
CVE-2017-6150 (HIGH CVSS 7.5) | Under certain conditions for F5 BIG | cvebase.io