CVE-2017-6137
- EPSS 0.7%
- Veröffentlicht 09.05.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, WebAccelerator, and WebSafe 11.6.1 HF1, 12.0.0 HF3, 12.0.0 HF4, and 12.1.0 through 12.1.2, undisclosed traffic patterns received while software SYN co...
CVE-2017-6128
- EPSS 0.93%
- Veröffentlicht 01.05.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An attacker may be able to cause a denial-of-service (DoS) attack against the sshd component in F5 BIG-IP, Enterprise Manager, BIG-IQ, and iWorkflow.
CVE-2016-9252
- EPSS 1.2%
- Veröffentlicht 27.03.2017 18:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Traffic Management Microkernel (TMM) in F5 BIG-IP before 11.5.4 HF3, 11.6.x before 11.6.1 HF2 and 12.x before 12.1.2 does not properly handle minimum path MTU options for IPv6, which allows remote attackers to cause a denial-of-service (DoS) thro...
CVE-2016-7474
- EPSS 0.11%
- Veröffentlicht 27.03.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In some cases the MCPD binary cache in F5 BIG-IP devices may allow a user with Advanced Shell access, or privileges to generate a qkview, to temporarily obtain normally unrecoverable information.
CVE-2016-7468
- EPSS 0.92%
- Veröffentlicht 23.03.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An unauthenticated remote attacker may be able to disrupt services on F5 BIG-IP 11.4.1 - 11.5.4 devices with maliciously crafted network traffic. This vulnerability affects virtual servers associated with TCP profiles when the BIG-IP system's tm.tcpp...
CVE-2016-9245
- EPSS 0.66%
- Veröffentlicht 07.03.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In F5 BIG-IP systems 12.1.0 - 12.1.2, malicious requests made to virtual servers with an HTTP profile can cause the TMM to restart. The issue is exposed with BIG-IP APM profiles, regardless of settings. The issue is also exposed with the non-default ...
CVE-2016-6249
- EPSS 0.06%
- Veröffentlicht 20.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in plaintext to /var/log/restjavad.0.log. It may allow local users to obtain sensitive information by r...
CVE-2016-9244
- EPSS 73.65%
- Veröffentlicht 09.02.2017 15:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL...
CVE-2016-9249
- EPSS 0.77%
- Veröffentlicht 31.01.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An undisclosed traffic pattern received by a BIG-IP Virtual Server with TCP Fast Open enabled may cause the Traffic Management Microkernel (TMM) to restart, resulting in a Denial-of-Service (DoS).
CVE-2016-9247
- EPSS 0.77%
- Veröffentlicht 10.01.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Under certain conditions for BIG-IP systems using a virtual server with an associated FastL4 profile and TCP analytics profile, a specific sequence of packets may cause the Traffic Management Microkernel (TMM) to restart.