ID

VAR-201508-0286


CVE

CVE-2015-5058


TITLE

plural F5 BIG-IP Service disruption in product virtual server components (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2015-004461

DESCRIPTION

Memory leak in the virtual server component in F5 Big-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.5.x before 11.5.1 HF10, 11.5.3 before HF1, and 11.6.0 before HF5, BIG-IQ Cloud, Device, and Security 4.4.0 through 4.5.0, and BIG-IQ ADC 4.5.0 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted ICMP packets. F5 BIG-IP LTM, etc. are all products of F5 Company in the United States. LTM is a local traffic manager; APM is a solution that provides secure unified access to business-critical applications and networks. Virtual server is one of the virtual server software components. The following products and versions are affected: F5 Big-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, PEM 11.5.1 11.5.x before HF10, 11.5.3 before HF1, 11.6 before HF5. 0 version; BIG-IQ Cloud, Device, Security version 4.4.0 to 4.5.0 version; BIG-IQ ADC version 4.5.0

Trust: 1.71

sources: NVD: CVE-2015-5058 // JVNDB: JVNDB-2015-004461 // VULHUB: VHN-83019

AFFECTED PRODUCTS

vendor:f5model:big-iq cloudscope:eqversion:4.4.0

Trust: 1.6

vendor:f5model:big-iq adcscope:eqversion:4.5.0

Trust: 1.6

vendor:f5model:big-ip link controllerscope:eqversion:11.5.3

Trust: 1.6

vendor:f5model:big-ip link controllerscope:eqversion:11.5.1

Trust: 1.6

vendor:f5model:big-ip link controllerscope:eqversion:11.6.0

Trust: 1.6

vendor:f5model:big-iq devicescope:eqversion:4.5.0

Trust: 1.6

vendor:f5model:big-iq securityscope:eqversion:4.4.0

Trust: 1.6

vendor:f5model:big-iq cloudscope:eqversion:4.5.0

Trust: 1.6

vendor:f5model:big-iq devicescope:eqversion:4.4.0

Trust: 1.6

vendor:f5model:big-iq securityscope:eqversion:4.5.0

Trust: 1.6

vendor:f5model:big-ip access policy managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:11.5.3

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:ltversion:11.5.x

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.5.1 hf10

Trust: 0.8

vendor:f5model:big-ip application security managerscope:eqversion:11.5.3 hf1

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.5.3 hf1

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.6.0 hf5

Trust: 0.8

vendor:f5model:big-ip access policy managerscope:ltversion:11.6.0

Trust: 0.8

vendor:f5model:big-ip analyticsscope:ltversion:11.6.0

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.1 hf10

Trust: 0.8

vendor:f5model:big-ip global traffic managerscope:eqversion:11.6.0 hf5

Trust: 0.8

vendor:f5model:big-ip analyticsscope:eqversion:11.5.1 hf10

Trust: 0.8

vendor:f5model:big-ip global traffic managerscope:eqversion:11.5.3 hf1

Trust: 0.8

vendor:f5model:big-ip access policy managerscope:ltversion:11.5.x

Trust: 0.8

vendor:f5model:big-ip application security managerscope:ltversion:11.5.3

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:ltversion:11.6.0

Trust: 0.8

vendor:f5model:big-ip analyticsscope:ltversion:11.5.x

Trust: 0.8

vendor:f5model:big-iq devicescope:eqversion:4.4.0 to 4.5.0

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope:ltversion:11.5.3

Trust: 0.8

vendor:f5model:big-ip link controllerscope:eqversion:11.5.3 hf1

Trust: 0.8

vendor:f5model:big-ip link controllerscope:eqversion:11.6.0 hf5

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:ltversion:11.5.x

Trust: 0.8

vendor:f5model:big-ip global traffic managerscope:ltversion:11.5.3

Trust: 0.8

vendor:f5model:big-ip link controllerscope:ltversion:11.5.3

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.6.0 hf5

Trust: 0.8

vendor:f5model:big-ip application security managerscope:eqversion:11.5.1 hf10

Trust: 0.8

vendor:f5model:big-ip access policy managerscope:eqversion:11.5.3 hf1

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.5.3 hf1

Trust: 0.8

vendor:f5model:big-iq securityscope:eqversion:4.4.0 to 4.5.0

Trust: 0.8

vendor:f5model:big-ip access policy managerscope:eqversion:11.6.0 hf5

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.5.1 hf10

Trust: 0.8

vendor:f5model:big-ip application security managerscope:ltversion:11.6.0

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope:ltversion:11.6.0

Trust: 0.8

vendor:f5model:big-ip global traffic managerscope:eqversion:11.5.1 hf10

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope:ltversion:11.5.3

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.5.3 hf1

Trust: 0.8

vendor:f5model:big-ip application security managerscope:ltversion:11.5.x

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope:ltversion:11.5.3

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope:ltversion:11.5.x

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.6.0 hf5

Trust: 0.8

vendor:f5model:big-ip global traffic managerscope:ltversion:11.6.0

Trust: 0.8

vendor:f5model:big-ip link controllerscope:eqversion:11.5.1 hf10

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:eqversion:11.6.0 hf5

Trust: 0.8

vendor:f5model:big-ip link controllerscope:ltversion:11.6.0

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.3 hf1

Trust: 0.8

vendor:f5model:big-ip global traffic managerscope:ltversion:11.5.x

Trust: 0.8

vendor:f5model:big-ip analyticsscope:eqversion:11.6.0 hf5

Trust: 0.8

vendor:f5model:big-ip access policy managerscope:ltversion:11.5.3

Trust: 0.8

vendor:f5model:big-ip analyticsscope:eqversion:11.5.3 hf1

Trust: 0.8

vendor:f5model:big-iq application delivery controllerscope:eqversion:4.5.0

Trust: 0.8

vendor:f5model:big-ip analyticsscope:ltversion:11.5.3

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.5.1 hf10

Trust: 0.8

vendor:f5model:big-ip link controllerscope:ltversion:11.5.x

Trust: 0.8

vendor:f5model:big-ip access policy managerscope:eqversion:11.5.1 hf10

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:ltversion:11.5.3

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope:ltversion:11.6.0

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope:ltversion:11.6.0

Trust: 0.8

vendor:f5model:big-iq cloudscope:eqversion:4.4.0 to 4.5.0

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope:ltversion:11.5.x

Trust: 0.8

vendor:f5model:big-ip application security managerscope:eqversion:11.6.0 hf5

Trust: 0.8

sources: JVNDB: JVNDB-2015-004461 // CNNVD: CNNVD-201508-509 // NVD: CVE-2015-5058

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-5058
value: HIGH

Trust: 1.0

NVD: CVE-2015-5058
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201508-509
value: HIGH

Trust: 0.6

VULHUB: VHN-83019
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2015-5058
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-83019
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-83019 // JVNDB: JVNDB-2015-004461 // CNNVD: CNNVD-201508-509 // NVD: CVE-2015-5058

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.9

sources: VULHUB: VHN-83019 // JVNDB: JVNDB-2015-004461 // NVD: CVE-2015-5058

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201508-509

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201508-509

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-004461

PATCH

title:sol17047: ICMP packet processing vulnerability CVE-2015-5058url:https://support.f5.com/kb/en-us/solutions/public/17000/000/sol17047.html

Trust: 0.8

sources: JVNDB: JVNDB-2015-004461

EXTERNAL IDS

db:NVDid:CVE-2015-5058

Trust: 2.5

db:SECTRACKid:1033334

Trust: 1.7

db:JVNDBid:JVNDB-2015-004461

Trust: 0.8

db:CNNVDid:CNNVD-201508-509

Trust: 0.7

db:VULHUBid:VHN-83019

Trust: 0.1

sources: VULHUB: VHN-83019 // JVNDB: JVNDB-2015-004461 // CNNVD: CNNVD-201508-509 // NVD: CVE-2015-5058

REFERENCES

url:https://support.f5.com/kb/en-us/solutions/public/17000/000/sol17047.html

Trust: 1.7

url:http://www.securitytracker.com/id/1033334

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-5058

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-5058

Trust: 0.8

sources: VULHUB: VHN-83019 // JVNDB: JVNDB-2015-004461 // CNNVD: CNNVD-201508-509 // NVD: CVE-2015-5058

SOURCES

db:VULHUBid:VHN-83019
db:JVNDBid:JVNDB-2015-004461
db:CNNVDid:CNNVD-201508-509
db:NVDid:CVE-2015-5058

LAST UPDATE DATE

2024-11-23T23:02:40.050000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-83019date:2015-08-26T00:00:00
db:JVNDBid:JVNDB-2015-004461date:2015-08-28T00:00:00
db:CNNVDid:CNNVD-201508-509date:2015-08-27T00:00:00
db:NVDid:CVE-2015-5058date:2024-11-21T02:32:14.270

SOURCES RELEASE DATE

db:VULHUBid:VHN-83019date:2015-08-24T00:00:00
db:JVNDBid:JVNDB-2015-004461date:2015-08-28T00:00:00
db:CNNVDid:CNNVD-201508-509date:2015-08-26T00:00:00
db:NVDid:CVE-2015-5058date:2015-08-24T14:59:05.773