Vulnerability Description
F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 are vulnerable to a denial of service attack when the MPTCP option is enabled on a virtual server. Data plane is vulnerable when using the MPTCP option of a TCP profile. There is no control plane exposure. An attacker may be able to disrupt services by causing TMM to restart hence temporarily failing to process traffic.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| F5 | Big-Ip Local Traffic Manager | 11.6.0 |
| F5 | Big-Ip Application Acceleration Manager | 11.6.0 |
| F5 | Big-Ip Advanced Firewall Manager | 11.6.0 |
| F5 | Big-Ip Access Policy Manager | 11.6.0 |
| F5 | Big-Ip Application Security Manager | 11.6.0 |
| F5 | Big-Ip Link Controller | 11.6.0 |
| F5 | Big-Ip Policy Enforcement Manager | 11.6.0 |
| F5 | Big-Ip Websafe | 1.0.0 |
References
- http://www.securityfocus.com/bid/101633Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039669Third Party AdvisoryVDB Entry
- https://support.f5.com/csp/article/K10002335Vendor Advisory
- http://www.securityfocus.com/bid/101633Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039669Third Party AdvisoryVDB Entry
- https://support.f5.com/csp/article/K10002335Vendor Advisory
FAQ
What is CVE-2017-6159?
CVE-2017-6159 is a vulnerability with a CVSS score of 5.9 (MEDIUM). F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 are vulnerable to a denial of service attack when the MPTCP op...
How severe is CVE-2017-6159?
CVE-2017-6159 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-6159?
Check the references section above for vendor advisories and patch information. Affected products include: F5 Big-Ip Local Traffic Manager, F5 Big-Ip Application Acceleration Manager, F5 Big-Ip Advanced Firewall Manager, F5 Big-Ip Access Policy Manager, F5 Big-Ip Application Security Manager.