5.9
CVE-2017-6162
- EPSS 1.52%
- Veröffentlicht 27.10.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle f5sirt@f5.com
- Teams Watchlist Login
- Unerledigt Login
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1, 11.4.0 to 11.5.4, 11.2.1, in some cases TMM may crash when processing TCP traffic. This vulnerability affects TMM via a virtual server configured with TCP profile. Traffic processing is disrupted while Traffic Management Microkernel (TMM) restarts. If the affected BIG-IP system is configured to be part of a device group, it will trigger a failover to the peer device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
F5 ≫ Big-ip Local Traffic Manager Version >= 11.5.0 <= 11.5.4
F5 ≫ Big-ip Local Traffic Manager Version11.2.1
F5 ≫ Big-ip Local Traffic Manager Version11.6.0
F5 ≫ Big-ip Local Traffic Manager Version11.6.1
F5 ≫ Big-ip Local Traffic Manager Version12.0.0
F5 ≫ Big-ip Local Traffic Manager Version12.1.0
F5 ≫ Big-ip Local Traffic Manager Version12.1.1
F5 ≫ Big-ip Application Acceleration Manager Version >= 11.5.0 <= 11.5.4
F5 ≫ Big-ip Application Acceleration Manager Version11.2.1
F5 ≫ Big-ip Application Acceleration Manager Version11.6.0
F5 ≫ Big-ip Application Acceleration Manager Version11.6.1
F5 ≫ Big-ip Application Acceleration Manager Version12.0.0
F5 ≫ Big-ip Application Acceleration Manager Version12.1.0
F5 ≫ Big-ip Application Acceleration Manager Version12.1.1
F5 ≫ Big-ip Advanced Firewall Manager Version >= 11.5.0 <= 11.5.4
F5 ≫ Big-ip Advanced Firewall Manager Version11.2.1
F5 ≫ Big-ip Advanced Firewall Manager Version11.6.0
F5 ≫ Big-ip Advanced Firewall Manager Version11.6.1
F5 ≫ Big-ip Advanced Firewall Manager Version12.0.0
F5 ≫ Big-ip Advanced Firewall Manager Version12.1.0
F5 ≫ Big-ip Advanced Firewall Manager Version12.1.1
F5 ≫ Big-ip Access Policy Manager Version >= 11.5.0 <= 11.5.4
F5 ≫ Big-ip Access Policy Manager Version11.2.1
F5 ≫ Big-ip Access Policy Manager Version11.6.0
F5 ≫ Big-ip Access Policy Manager Version11.6.1
F5 ≫ Big-ip Access Policy Manager Version12.0.0
F5 ≫ Big-ip Access Policy Manager Version12.1.0
F5 ≫ Big-ip Access Policy Manager Version12.1.1
F5 ≫ Big-ip Application Security Manager Version >= 11.5.0 <= 11.5.4
F5 ≫ Big-ip Application Security Manager Version11.2.1
F5 ≫ Big-ip Application Security Manager Version11.6.0
F5 ≫ Big-ip Application Security Manager Version11.6.1
F5 ≫ Big-ip Application Security Manager Version12.0.0
F5 ≫ Big-ip Application Security Manager Version12.1.0
F5 ≫ Big-ip Application Security Manager Version12.1.1
F5 ≫ Big-ip Link Controller Version >= 11.5.0 <= 11.5.4
F5 ≫ Big-ip Link Controller Version11.2.1
F5 ≫ Big-ip Link Controller Version11.6.0
F5 ≫ Big-ip Link Controller Version11.6.1
F5 ≫ Big-ip Link Controller Version12.0.0
F5 ≫ Big-ip Link Controller Version12.1.0
F5 ≫ Big-ip Link Controller Version12.1.1
F5 ≫ Big-ip Policy Enforcement Manager Version >= 11.5.0 <= 11.5.4
F5 ≫ Big-ip Policy Enforcement Manager Version11.2.1
F5 ≫ Big-ip Policy Enforcement Manager Version11.6.0
F5 ≫ Big-ip Policy Enforcement Manager Version11.6.1
F5 ≫ Big-ip Policy Enforcement Manager Version12.0.0
F5 ≫ Big-ip Policy Enforcement Manager Version12.1.0
F5 ≫ Big-ip Policy Enforcement Manager Version12.1.1
F5 ≫ Big-ip Websafe Version1.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.52% | 0.795 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.