PT-2018-17021 · F5 · F5 Big-Ip
Publicado
2018-06-27
·
Atualizado
2019-10-03
·
CVE-2018-5527
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP versions 13.1.0 through 13.1.0.7
Description
A remote attacker can force the Traffic Management Microkernel (tmm) to leak memory on virtual servers configured with a Client SSL or Server SSL profile that has the SSL Forward Proxy feature enabled. This results in increased system memory usage over time, potentially causing decreased performance or a system reboot due to memory exhaustion.
Recommendations
For F5 BIG-IP versions 13.1.0 through 13.1.0.7, consider disabling the SSL Forward Proxy feature as a temporary workaround to minimize the risk of memory leakage until a patch is available.
Correção
Missing Release of Resource after Effective Lifetime
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
F5 Big-Ip