CVE-2017-6166
published 2017-11-22CVE-2017-6166: In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12.0.0 to 12.1.1, in some cases the Traffic Management…
medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12.0.0 to 12.1.1, in some cases the Traffic Management Microkernel (TMM) may crash when processing fragmented packets. This vulnerability affects TMM through a virtual server configured with a FastL4 profile. Traffic processing is disrupted while TMM restarts. If the affected BIG-IP system is configured as part of a device group, it will trigger a failover to the peer device.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip_aam | — | — |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_afm | 12.0.0 – 12.1.1 | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 12.0.0 – 12.1.1 | — |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_apm | 12.0.0 – 12.1.1 | — |
| f5 | big-ip_application_acceleration_manager | 12.0.0 – 12.1.1 | — |
| f5 | big-ip_asm | — | — |
| f5 | big-ip_asm | 12.0.0 – 12.1.1 | — |
| f5 | big-ip_dns | — | — |
| f5 | big-ip_dns | 12.0.0 – 12.1.1 | — |
| f5 | big-ip_link_controller | — | — |
| f5 | big-ip_link_controller | 12.0.0 – 12.1.1 | — |
| f5 | big-ip_ltm | — | — |
| f5 | big-ip_ltm | 12.0.0 – 12.1.1 | — |
| f5 | big-ip_pem | — | — |
| f5 | big-ip_pem | 12.0.0 – 12.1.1 | — |
| f5 | f5_websafe | — | — |
| f5 | f5_websafe | 12.0.0 – 12.1.1 | — |
| f5 | linerate | — | — |
| f5 | linerate | 2.5.0 – 2.6.2 | — |
F5
CVE-2017-6166: In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12
vendor_f5·2017-11-22·CVSS 5.9
CVE-2017-6166 [MEDIUM] CWE-415 CVE-2017-6166: In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12
CVE-2017-6166: In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12
In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12.0.0 to 12.1.1, in some cases the Traffic Management Microkernel (TMM) may crash when processing fragmented packets. This vulnerability affects TMM through a virtual server configured with a FastL4 profile. Traffic processing is disrupted while TMM restarts. If the affected BIG-IP system is configured as part of a device group, it will trigger a failover to the peer device.
Affected Products: BIG-IP AAM, BIG-IP Analytics, BIG-IP LTM, BIG-IP Link Controller, Big-Ip Afm, Big-Ip Apm, Big-Ip Asm, Big-Ip Dns, Big-Ip Ltm, Big-Ip Pem, F5 Websafe, Linerate
Affected Versions: 12.0.0 - 12.1.1;
GHSA
GHSA-j35v-h5m8-p59m: In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12
ghsa_unreviewed·2022-05-13
CVE-2017-6166 [MEDIUM] CWE-415 GHSA-j35v-h5m8-p59m: In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12
In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12.0.0 to 12.1.1, in some cases the Traffic Management Microkernel (TMM) may crash when processing fragmented packets. This vulnerability affects TMM through a virtual server configured with a FastL4 profile. Traffic processing is disrupted while TMM restarts. If the affected BIG-IP system is configured as part of a device group, it will trigger a failover to the peer device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-11-22
Published