HIGH · 7.5

CVE-2016-6876

The RESOLV::lookup iRule command in F5 BIG-IP LTM, APM, ASM, and Link Controller 10.2.1 through 10.2.4, 11.2.1, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.0.0 before HF3; BIG-IP AA...

Vulnerability Description

The RESOLV::lookup iRule command in F5 BIG-IP LTM, APM, ASM, and Link Controller 10.2.1 through 10.2.4, 11.2.1, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.0.0 before HF3; BIG-IP AAM, AFM, and PEM 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.0.0 before HF3; BIG-IP Analytics 11.2.1, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.0.0 before HF3; BIG-IP DNS 12.0.0 before HF3; BIG-IP Edge Gateway, WebAccelerator, and WOM 10.2.1 through 10.2.4 and 11.2.1; BIG-IP GTM 10.2.1 through 10.2.4, 11.2.1, 11.4.x, 11.5.x before 11.5.4 HF2, and 11.6.x before 11.6.1; and BIG-IP PSM 10.2.1 through 10.2.4 and 11.4.0 through 11.4.1 allows remote DNS servers to cause a denial of service (CPU consumption or Traffic Management Microkernel crash) via a crafted PTR response.

CVSS Score

7.5

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
F5Big-Ip Local Traffic Manager10.2.1
F5Big-Ip Webaccelerator10.2.1
F5Big-Ip Application Acceleration Manager11.4.0
F5Big-Ip Global Traffic Manager10.2.1
F5Big-Ip Link Controller10.2.1
F5Big-Ip Advanced Firewall Manager11.4.0
F5Big-Ip Protocol Security Module10.2.1
F5Big-Ip Wan Optimization Manager10.2.1
F5Big-Ip Application Security Manager10.2.1
F5Big-Ip Policy Enforcement Manager11.4.0
F5Big-Ip Domain Name System12.0.0
F5Big-Ip Analytics11.2.1
F5Big-Ip Edge Gateway10.2.1
F5Big-Ip Access Policy Manager10.2.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-6876?

CVE-2016-6876 is a vulnerability with a CVSS score of 7.5 (HIGH). The RESOLV::lookup iRule command in F5 BIG-IP LTM, APM, ASM, and Link Controller 10.2.1 through 10.2.4, 11.2.1, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.0.0 before HF3; BIG-IP AA...

How severe is CVE-2016-6876?

CVE-2016-6876 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-6876?

Check the references section above for vendor advisories and patch information. Affected products include: F5 Big-Ip Local Traffic Manager, F5 Big-Ip Webaccelerator, F5 Big-Ip Application Acceleration Manager, F5 Big-Ip Global Traffic Manager, F5 Big-Ip Link Controller.