[Forgot Password]
Login  Register Subscribe

23631

 
 

126951

 
 

99602

 
 

909

 
 

80130

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2017-6159

Date: (C)2017-10-30   (M)2017-12-13 


F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 are vulnerable to a denial of service attack when the MPTCP option is enabled on a virtual server. Data plane is vulnerable when using the MPTCP option of a TCP profile. There is no control plane exposure. An attacker may be able to disrupt services by causing TMM to restart hence temporarily failing to process traffic.

CVSS Score: 4.3Access Vector: NETWORK
Exploit Score: 8.6Access Complexity: MEDIUM
Impact Score: 2.9Authentication: NONE
 Confidentiality: NONE
 Integrity: NONE
 Availability: PARTIAL





Reference:
BID-101633
SECTRACK-1039669
https://support.f5.com/csp/article/K10002335

CPE    21
cpe:/a:f5:big-ip_local_traffic_manager:12.0.0
cpe:/a:f5:big-ip_policy_enforcement_manager:12.1.1
cpe:/a:f5:big-ip_policy_enforcement_manager:12.0.0
cpe:/a:f5:big-ip_application_security_manager:12.1.1
...
CWE    1
CWE-399

© 2013 SecPod Technologies