PT-2017-16918 · F5 · Big-Ip

Published

2017-10-27

·

Updated

2019-10-03

·

CVE-2017-6159

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions F5 BIG-IP software versions 11.6.0 through 11.6.1 F5 BIG-IP software versions 12.0.0 through 12.1.2
Description The issue allows for a denial of service attack when the MPTCP option is enabled on a virtual server. This affects the data plane when using the MPTCP option of a TCP profile, with no control plane exposure. An attacker may disrupt services by causing TMM to restart, temporarily failing to process traffic.
Recommendations For versions 11.6.0 through 11.6.1, consider disabling the MPTCP option on virtual servers to prevent exploitation. For versions 12.0.0 through 12.1.2, consider disabling the MPTCP option on virtual servers to prevent exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-6159

Affected Products

Big-Ip