PT-2017-16919 · F5 · F5 Big-Ip Pem+1

Published

2017-10-27

·

Updated

2019-10-03

·

CVE-2017-6160

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions F5 BIG-IP AAM and PEM software versions 11.4.1 through 11.5.4 F5 BIG-IP AAM and PEM software versions 11.6.0 through 11.6.1 F5 BIG-IP AAM and PEM software versions 12.0.0 through 12.1.1
Description A remote attacker may create maliciously crafted HTTP requests to cause the Traffic Management Microkernel (TMM) to restart and temporarily fail to process traffic. This issue is exposed on virtual servers using a Policy Enforcement profile or a Web Acceleration profile. Systems without the BIG-IP AAM or PEM module provisioned are not vulnerable.
Recommendations For versions 11.4.1 through 11.5.4, consider disabling the Policy Enforcement profile or Web Acceleration profile as a temporary workaround until a patch is available. For versions 11.6.0 through 11.6.1, consider disabling the Policy Enforcement profile or Web Acceleration profile as a temporary workaround until a patch is available. For versions 12.0.0 through 12.1.1, consider disabling the Policy Enforcement profile or Web Acceleration profile as a temporary workaround until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-6160

Affected Products

F5 Big-Ip Apm
F5 Big-Ip Pem