MEDIUM · 5.0

CVE-2015-4638

The FastL4 virtual server in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.3.0 through 11.5.2 and 11.6.0 through 11.6.0 HF4, BIG-IP Edge Gateway, WebAccelerator, and W...

Vulnerability Description

The FastL4 virtual server in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.3.0 through 11.5.2 and 11.6.0 through 11.6.0 HF4, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.2.1 through 11.3.0, and BIG-IP PSM 11.2.1 through 11.4.1 allows remote attackers to cause a denial of service (Traffic Management Microkernel restart) via a fragmented packet.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
F5Big-Ip Advanced Firewall Manager11.3.0
F5Big-Ip Analytics11.3.0
F5Big-Ip Application Security Manager11.3.0
F5Big-Ip Edge Gateway11.2.1
F5Big-Ip Global Traffic Manager11.3.0
F5Big-Ip Link Controller11.3.0
F5Big-Ip Local Traffic Manager11.3.0
F5Big-Ip Policy Enforcement Manager11.3.0
F5Big-Ip Protocol Security Module11.2.1
F5Big-Ip Webaccelerator11.2.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-4638?

CVE-2015-4638 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The FastL4 virtual server in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.3.0 through 11.5.2 and 11.6.0 through 11.6.0 HF4, BIG-IP Edge Gateway, WebAccelerator, and W...

How severe is CVE-2015-4638?

CVE-2015-4638 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-4638?

Check the references section above for vendor advisories and patch information. Affected products include: F5 Big-Ip Advanced Firewall Manager, F5 Big-Ip Analytics, F5 Big-Ip Application Security Manager, F5 Big-Ip Edge Gateway, F5 Big-Ip Global Traffic Manager.