PT-2018-17021 · F5 · F5 Big-Ip
Published
2018-06-27
·
Updated
2019-10-03
·
CVE-2018-5527
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP versions 13.1.0 through 13.1.0.7
Description
A remote attacker can force the Traffic Management Microkernel (tmm) to leak memory on virtual servers configured with a Client SSL or Server SSL profile that has the SSL Forward Proxy feature enabled. This results in increased system memory usage over time, potentially causing decreased performance or a system reboot due to memory exhaustion.
Recommendations
For F5 BIG-IP versions 13.1.0 through 13.1.0.7, consider disabling the SSL Forward Proxy feature as a temporary workaround to minimize the risk of memory leakage until a patch is available.
Fix
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
F5 Big-Ip