5.9
CVE-2016-9245
- EPSS 0.66%
- Published 07.03.2017 21:59:00
- Last modified 20.04.2025 01:37:25
- Source f5sirt@f5.com
- Teams watchlist Login
- Open Login
In F5 BIG-IP systems 12.1.0 - 12.1.2, malicious requests made to virtual servers with an HTTP profile can cause the TMM to restart. The issue is exposed with BIG-IP APM profiles, regardless of settings. The issue is also exposed with the non-default "Normalize URI" configuration options used in iRules and/or BIG-IP LTM policies. An attacker may be able to disrupt traffic or cause the BIG-IP system to fail over to another device in the device group.
Data is provided by the National Vulnerability Database (NVD)
F5 ≫ Big-ip Local Traffic Manager Version12.1.0
F5 ≫ Big-ip Local Traffic Manager Version12.1.1
F5 ≫ Big-ip Local Traffic Manager Version12.1.2
F5 ≫ Big-ip Application Acceleration Manager Version12.1.0
F5 ≫ Big-ip Application Acceleration Manager Version12.1.1
F5 ≫ Big-ip Application Acceleration Manager Version12.1.2
F5 ≫ Big-ip Advanced Firewall Manager Version12.1.0
F5 ≫ Big-ip Advanced Firewall Manager Version12.1.1
F5 ≫ Big-ip Advanced Firewall Manager Version12.1.2
F5 ≫ Big-ip Analytics Version12.1.0
F5 ≫ Big-ip Analytics Version12.1.1
F5 ≫ Big-ip Analytics Version12.1.2
F5 ≫ Big-ip Access Policy Manager Version12.1.0
F5 ≫ Big-ip Access Policy Manager Version12.1.1
F5 ≫ Big-ip Access Policy Manager Version12.1.2
F5 ≫ Big-ip Application Security Manager Version12.1.0
F5 ≫ Big-ip Application Security Manager Version12.1.1
F5 ≫ Big-ip Application Security Manager Version12.1.2
F5 ≫ Big-ip Domain Name System Version12.1.0
F5 ≫ Big-ip Domain Name System Version12.1.1
F5 ≫ Big-ip Domain Name System Version12.1.2
F5 ≫ Big-ip Link Controller Version12.1.0
F5 ≫ Big-ip Link Controller Version12.1.1
F5 ≫ Big-ip Link Controller Version12.1.2
F5 ≫ Big-ip Policy Enforcement Manager Version12.1.0
F5 ≫ Big-ip Policy Enforcement Manager Version12.1.1
F5 ≫ Big-ip Policy Enforcement Manager Version12.1.2
F5 ≫ Big-ip Websafe Version12.1.0
F5 ≫ Big-ip Websafe Version12.1.1
F5 ≫ Big-ip Websafe Version12.1.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.66% | 0.685 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.