PT-2016-1625 · F5 · Aam+7

Publicado

2016-01-12

·

Atualizado

2016-01-15

·

CVE-2015-7759

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM versions 12.0.0 through 12.0.0 before HF1
Description The issue is related to the Congestion Metrics Cache feature in the TCP profile for a virtual server, allowing remote attackers to cause a denial of service (Traffic Management Microkernel (TMM) restart) via crafted ICMP packets. This is connected to Path MTU (PMTU) discovery. The vulnerability exists due to insufficient input validation, which can be exploited by a remote attacker using specially crafted ICMP packets to cause a denial of service.
Recommendations For BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM versions 12.0.0 through 12.0.0 before HF1, consider disabling the Congestion Metrics Cache feature in the TCP profile for virtual servers as a temporary workaround until a patch is available. Restrict access to the vulnerable systems to minimize the risk of exploitation. Apply the HF1 patch to resolve the issue.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00936
CVE-2015-7759

Produtos afetados

Aam
Afm
Apm
Asm
Analytics
Big-Ip Ltm
Link Controller
Pem