SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-6162

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1, 11.4.0 to 11.5.4, 11.2.1, in some cases TMM may crash when processing TCP traffic.

MEDIUM 5.9EPSS 1.67%

Does this matter?

Lower severity and a low EPSS score (1.67%). Track it; it rarely justifies an emergency change on its own.

Description

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1, 11.4.0 to 11.5.4, 11.2.1, in some cases TMM may crash when processing TCP traffic. This vulnerability affects TMM via a virtual server configured with TCP profile. Traffic processing is disrupted while Traffic Management Microkernel (TMM) restarts. If the affected BIG-IP system is configured to be part of a device group, it will trigger a failover to the peer device.

CVSS 3.0
5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
1.67% probability · 76th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
f5/big-ip local traffic manager · f5/big-ip application acceleration manager · f5/big-ip advanced firewall manager · f5/big-ip access policy manager · f5/big-ip application security manager · f5/big-ip link controller · f5/big-ip policy enforcement manager · f5/big-ip websafe
Source
f5sirt@f5.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.