Vulnerability Description
On the BIG-IP 2000s, 2200s, 4000s, 4200v, i5600, i5800, i7600, i7800, i10600,i10800, and VIPRION 4450 blades, running version 11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.6.0, 11.6.1, 12.0.0, 12.1.0, 12.1.1 or 12.1.2 of BIG-IP LTM, AAM, AFM, Analytics, ASM, DNS, GTM or PEM, an undisclosed sequence of packets sent to Virtual Servers with client or server SSL profiles may cause disruption of data plane services.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Ip Local Traffic Manager | 11.5.0 |
| F5 | Big-Ip 2000S | - |
| F5 | Big-Ip 2200S | - |
| F5 | Big-Ip 4000S | - |
| F5 | Big-Ip 4200V | - |
| F5 | Big-Ip I10600 | - |
| F5 | Big-Ip I10800 | - |
| F5 | Big-Ip I5600 | - |
| F5 | Big-Ip I5800 | - |
| F5 | Big-Ip I7600 | - |
| F5 | Big-Ip I7800 | - |
| F5 | Viprion 4450 Blades | - |
| F5 | Big-Ip Application Acceleration Manager | 11.5.0 |
| F5 | Big-Ip Advanced Firewall Manager | 11.5.0 |
| F5 | Big-Ip Analytics | 11.5.0 |
| F5 | Big-Ip Application Security Manager | 11.5.0 |
| F5 | Big-Ip Dns | 11.5.0 |
| F5 | Big-Ip Global Traffic Manager | 11.5.0 |
| F5 | Big-Ip Policy Enforcement Manager | 11.5.0 |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1040042Third Party AdvisoryVDB Entry
- https://support.f5.com/csp/article/K55102452Issue TrackingVendor Advisory
- http://www.securitytracker.com/id/1040042Third Party AdvisoryVDB Entry
- https://support.f5.com/csp/article/K55102452Issue TrackingVendor Advisory
FAQ
What is CVE-2017-6140?
CVE-2017-6140 is a vulnerability with a CVSS score of 7.5 (HIGH). On the BIG-IP 2000s, 2200s, 4000s, 4200v, i5600, i5800, i7600, i7800, i10600,i10800, and VIPRION 4450 blades, running version 11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.6.0, 11.6.1, 12.0.0, 12.1.0, 12...
How severe is CVE-2017-6140?
CVE-2017-6140 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-6140?
Check the references section above for vendor advisories and patch information. Affected products include: F5 Big-Ip Local Traffic Manager, F5 Big-Ip 2000S, F5 Big-Ip 2200S, F5 Big-Ip 4000S, F5 Big-Ip 4200V.