ID

VAR-201509-0421


CVE

CVE-2015-4638


TITLE

plural F5 BIG-IP Product FastL4 Service disruption in virtual servers (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2015-004935

DESCRIPTION

The FastL4 virtual server in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.3.0 through 11.5.2 and 11.6.0 through 11.6.0 HF4, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.2.1 through 11.3.0, and BIG-IP PSM 11.2.1 through 11.4.1 allows remote attackers to cause a denial of service (Traffic Management Microkernel restart) via a fragmented packet. F5 BIG-IP LTM, etc. are all products of F5 Company in the United States. LTM is a local traffic manager; APM is a solution that provides secure unified access to business-critical applications and networks. A security vulnerability exists in the FastL4 virtual server of several F5 products

Trust: 1.71

sources: NVD: CVE-2015-4638 // JVNDB: JVNDB-2015-004935 // VULHUB: VHN-82599

AFFECTED PRODUCTS

vendor:f5model:big-ip protocol security modulescope:eqversion:11.4.1

Trust: 1.6

vendor:f5model:big-ip analyticsscope:eqversion:11.5.2

Trust: 1.6

vendor:f5model:big-ip application security managerscope:eqversion:11.5.1

Trust: 1.6

vendor:f5model:big-ip local traffic managerscope:eqversion:11.6.0

Trust: 1.6

vendor:f5model:big-ip application security managerscope:eqversion:11.4.0

Trust: 1.6

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.1

Trust: 1.6

vendor:f5model:big-ip application security managerscope:eqversion:11.5.0

Trust: 1.6

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.2

Trust: 1.6

vendor:f5model:big-ip analyticsscope:eqversion:11.5.1

Trust: 1.6

vendor:f5model:big-ip application security managerscope:eqversion:11.4.1

Trust: 1.6

vendor:f5model:big-ip local traffic managerscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip edge gatewayscope:eqversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip protocol security modulescope:eqversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.5.2

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:11.3.0

Trust: 1.0

vendor:f5model:big-ip webacceleratorscope:eqversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip global traffic managerscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.5.1

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.4.1

Trust: 1.0

vendor:f5model:big-ip analyticsscope:eqversion:11.4.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.2.1 to 11.5.2

Trust: 0.8

vendor:f5model:big-ip access policy managerscope:eqversion:11.6.0 to 11.6.0 hf4

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.3.0 to 11.5.2

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.6.0 to 11.6.0 hf4

Trust: 0.8

vendor:f5model:big-ip analyticsscope:eqversion:11.2.1 to 11.5.2

Trust: 0.8

vendor:f5model:big-ip analyticsscope:eqversion:11.6.0 to 11.6.0 hf4

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.4.0 to 11.5.2

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.6.0 to 11.6.0 hf4

Trust: 0.8

vendor:f5model:big-ip application security managerscope:eqversion:11.2.1 to 11.5.2

Trust: 0.8

vendor:f5model:big-ip application security managerscope:eqversion:11.6.0 to 11.6.0 hf4

Trust: 0.8

vendor:f5model:big-ip edge gatewayscope:eqversion:11.2.1 to 11.3.0

Trust: 0.8

vendor:f5model:big-ip global traffic managerscope:eqversion:11.2.1 to 11.5.2

Trust: 0.8

vendor:f5model:big-ip global traffic managerscope:eqversion:11.6.0 to 11.6.0 hf4

Trust: 0.8

vendor:f5model:big-ip link controllerscope:eqversion:11.2.1 to 11.5.2

Trust: 0.8

vendor:f5model:big-ip link controllerscope:eqversion:11.6.0 to 11.6.0 hf4

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:eqversion:11.2.1 to 11.5.2

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:eqversion:11.6.0 to 11.6.0 hf4

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.3.0 to 11.5.2

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.6.0 to 11.6.0 hf4

Trust: 0.8

vendor:f5model:big-ip protocol security modulescope:eqversion:11.2.1 to 11.4.1

Trust: 0.8

vendor:f5model:big-ip wan optimization managerscope:eqversion:11.2.1 to 11.3.0

Trust: 0.8

vendor:f5model:big-ip webacceleratorscope:eqversion:11.2.1 to 11.3.0

Trust: 0.8

sources: JVNDB: JVNDB-2015-004935 // CNNVD: CNNVD-201509-369 // NVD: CVE-2015-4638

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-4638
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-4638
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201509-369
value: MEDIUM

Trust: 0.6

VULHUB: VHN-82599
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-4638
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-82599
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-82599 // JVNDB: JVNDB-2015-004935 // CNNVD: CNNVD-201509-369 // NVD: CVE-2015-4638

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-82599 // JVNDB: JVNDB-2015-004935 // NVD: CVE-2015-4638

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201509-369

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201509-369

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-004935

PATCH

title:sol17155: TMM vulnerabilityurl:https://support.f5.com/kb/en-us/solutions/public/17000/100/sol17155.html

Trust: 0.8

sources: JVNDB: JVNDB-2015-004935

EXTERNAL IDS

db:NVDid:CVE-2015-4638

Trust: 2.5

db:SECTRACKid:1033578

Trust: 1.7

db:JVNDBid:JVNDB-2015-004935

Trust: 0.8

db:CNNVDid:CNNVD-201509-369

Trust: 0.7

db:VULHUBid:VHN-82599

Trust: 0.1

sources: VULHUB: VHN-82599 // JVNDB: JVNDB-2015-004935 // CNNVD: CNNVD-201509-369 // NVD: CVE-2015-4638

REFERENCES

url:https://support.f5.com/kb/en-us/solutions/public/17000/100/sol17155.html

Trust: 1.7

url:http://www.securitytracker.com/id/1033578

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-4638

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-4638

Trust: 0.8

sources: VULHUB: VHN-82599 // JVNDB: JVNDB-2015-004935 // CNNVD: CNNVD-201509-369 // NVD: CVE-2015-4638

SOURCES

db:VULHUBid:VHN-82599
db:JVNDBid:JVNDB-2015-004935
db:CNNVDid:CNNVD-201509-369
db:NVDid:CVE-2015-4638

LAST UPDATE DATE

2024-11-23T22:13:22.999000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-82599date:2015-09-22T00:00:00
db:JVNDBid:JVNDB-2015-004935date:2015-09-30T00:00:00
db:CNNVDid:CNNVD-201509-369date:2015-09-24T00:00:00
db:NVDid:CVE-2015-4638date:2024-11-21T02:31:27.213

SOURCES RELEASE DATE

db:VULHUBid:VHN-82599date:2015-09-18T00:00:00
db:JVNDBid:JVNDB-2015-004935date:2015-09-30T00:00:00
db:CNNVDid:CNNVD-201509-369date:2015-09-21T00:00:00
db:NVDid:CVE-2015-4638date:2015-09-18T14:59:00.097