CVE-2019-6631
On BIG-IP 11.5.1-11.6.4, iRules performing HTTP header manipulation may cause an interruption to service when processing traffic handled by a Virtual Server with an associated HTTP profile, in specific circumstances, when the requests do not strictly…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.53%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
On BIG-IP 11.5.1-11.6.4, iRules performing HTTP header manipulation may cause an interruption to service when processing traffic handled by a Virtual Server with an associated HTTP profile, in specific circumstances, when the requests do not strictly conform to RFCs.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.53% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- f5/big-ip local traffic manager · f5/big-ip application acceleration manager · f5/big-ip advanced firewall manager · f5/big-ip analytics · f5/big-ip access policy manager · f5/big-ip application security manager · f5/big-ip domain name system · f5/big-ip edge gateway · f5/big-ip global traffic manager · f5/big-ip link controller · f5/big-ip policy enforcement manager · f5/big-ip webaccelerator · f5/big-ip websafe
- Source
- f5sirt@f5.com
References
- http://www.securityfocus.com/bid/109119Broken Link, Third Party Advisory, VDB Entry
- https://support.f5.com/csp/article/K19501795Vendor Advisory
- https://support.f5.com/csp/article/K19501795?utm_source=f5support&%3Butm_medium=RSS
- http://www.securityfocus.com/bid/109119Broken Link, Third Party Advisory, VDB Entry
- https://support.f5.com/csp/article/K19501795Vendor Advisory
- https://support.f5.com/csp/article/K19501795?utm_source=f5support&%3Butm_medium=RSS
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.