PT-2017-16919 · F5 · F5 Big-Ip Pem+1
Published
2017-10-27
·
Updated
2019-10-03
·
CVE-2017-6160
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP AAM and PEM software versions 11.4.1 through 11.5.4
F5 BIG-IP AAM and PEM software versions 11.6.0 through 11.6.1
F5 BIG-IP AAM and PEM software versions 12.0.0 through 12.1.1
Description
A remote attacker may create maliciously crafted HTTP requests to cause the Traffic Management Microkernel (TMM) to restart and temporarily fail to process traffic. This issue is exposed on virtual servers using a Policy Enforcement profile or a Web Acceleration profile. Systems without the BIG-IP AAM or PEM module provisioned are not vulnerable.
Recommendations
For versions 11.4.1 through 11.5.4, consider disabling the Policy Enforcement profile or Web Acceleration profile as a temporary workaround until a patch is available.
For versions 11.6.0 through 11.6.1, consider disabling the Policy Enforcement profile or Web Acceleration profile as a temporary workaround until a patch is available.
For versions 12.0.0 through 12.1.1, consider disabling the Policy Enforcement profile or Web Acceleration profile as a temporary workaround until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
F5 Big-Ip Apm
F5 Big-Ip Pem