Rapid7 Vulnerability & Exploit Database

F5 Networks: K13421245 (CVE-2017-6162): TMM vulnerability CVE-2017-6162

Back to Search

F5 Networks: K13421245 (CVE-2017-6162): TMM vulnerability CVE-2017-6162

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
10/26/2017
Created
07/25/2018
Added
10/28/2017
Modified
02/01/2018

Description

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1, 11.4.0 to 11.5.4, 11.2.1, in some cases TMM may crash when processing TCP traffic. This vulnerability affects TMM via a virtual server configured with TCP profile. Traffic processing is disrupted while Traffic Management Microkernel (TMM) restarts. If the affected BIG-IP system is configured to be part of a device group, it will trigger a failover to the peer device.

Solution(s)

  • f5-big-ip-upgrade-latest

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;