CVE-2017-6166

Published: Nov 22, 2017 Last Modified: Apr 20, 2025 EU-VD ID: EUVD-2017-15231 Aliases: GSD-2017-6166
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,9
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
MEDIUM 4,3
Access Vector: network
Access Complexity: medium
Authentication: none
Confidentiality: none
Integrity: none
Availability: partial

Description

AI Translation Available

In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12.0.0 to 12.1.1, in some cases the Traffic Management Microkernel (TMM) may crash when processing fragmented packets. This vulnerability affects TMM through a virtual server configured with a FastL4 profile. Traffic processing is disrupted while TMM restarts. If the affected BIG-IP system is configured as part of a device group, it will trigger a failover to the peer device.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0120
Percentile
0,8th
Updated

EPSS Score Trend (Last 90 Days)

415

Double Free

Draft
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability
Potential Impacts:
Modify Memory Execute Unauthorized Code Or Commands
Applicable Platforms
Languages: C, C++, Memory-Unsafe
View CWE Details
Application

Big-Ip Application Acceleration Manager by F5

Version Range Affected
From 12.0.0 (inclusive)
To 12.1.1 (inclusive)
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

F5 Websafe by F5

Version Range Affected
From 12.0.0 (inclusive)
To 12.1.1 (inclusive)
cpe:2.3:a:f5:f5_websafe:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Afm by F5

Version Range Affected
From 12.0.0 (inclusive)
To 12.1.1 (inclusive)
cpe:2.3:a:f5:big-ip_afm:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Link Controller by F5

Version Range Affected
From 12.0.0 (inclusive)
To 12.1.1 (inclusive)
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Analytics by F5

Version Range Affected
From 12.0.0 (inclusive)
To 12.1.1 (inclusive)
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Apm by F5

Version Range Affected
From 12.0.0 (inclusive)
To 12.1.1 (inclusive)
cpe:2.3:a:f5:big-ip_apm:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Pem by F5

Version Range Affected
From 12.0.0 (inclusive)
To 12.1.1 (inclusive)
cpe:2.3:a:f5:big-ip_pem:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Ltm by F5

Version Range Affected
From 12.0.0 (inclusive)
To 12.1.1 (inclusive)
cpe:2.3:a:f5:big-ip_ltm:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Linerate by F5

Version Range Affected
From 2.5.0 (inclusive)
To 2.6.2 (inclusive)
cpe:2.3:a:f5:linerate:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Dns by F5

Version Range Affected
From 12.0.0 (inclusive)
To 12.1.1 (inclusive)
cpe:2.3:a:f5:big-ip_dns:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Big-Ip Asm by F5

Version Range Affected
From 12.0.0 (inclusive)
To 12.1.1 (inclusive)
cpe:2.3:a:f5:big-ip_asm:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://support.f5.com/csp/article/K65615624
Issue Tracking Mitigation Vendor Advisory
https://support.f5.com/csp/article/K65615624
http://www.securityfocus.com/bid/102264
Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/102264
http://www.securitytracker.com/id/1039949
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1039949
https://support.f5.com/csp/article/K65615624
Issue Tracking Mitigation Vendor Advisory
https://support.f5.com/csp/article/K65615624
http://www.securityfocus.com/bid/102264
Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/102264
http://www.securitytracker.com/id/1039949
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1039949