PT-2017-16918 · F5 · Big-Ip
Published
2017-10-27
·
Updated
2019-10-03
·
CVE-2017-6159
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP software versions 11.6.0 through 11.6.1
F5 BIG-IP software versions 12.0.0 through 12.1.2
Description
The issue allows for a denial of service attack when the MPTCP option is enabled on a virtual server. This affects the data plane when using the MPTCP option of a TCP profile, with no control plane exposure. An attacker may disrupt services by causing TMM to restart, temporarily failing to process traffic.
Recommendations
For versions 11.6.0 through 11.6.1, consider disabling the MPTCP option on virtual servers to prevent exploitation.
For versions 12.0.0 through 12.1.2, consider disabling the MPTCP option on virtual servers to prevent exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Big-Ip