ID

VAR-201710-1314


CVE

CVE-2017-6162


TITLE

plural F5 BIG-IP Product buffer error vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2017-009799

DESCRIPTION

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1, 11.4.0 to 11.5.4, 11.2.1, in some cases TMM may crash when processing TCP traffic. This vulnerability affects TMM via a virtual server configured with TCP profile. Traffic processing is disrupted while Traffic Management Microkernel (TMM) restarts. If the affected BIG-IP system is configured to be part of a device group, it will trigger a failover to the peer device. plural F5 BIG-IP The product contains a buffer error vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. Multiple F5 BIG-IP products are prone to a denial-of-service vulnerability. A remote attacker can exploit this issue to cause the service to restart resulting in a denial-of-service condition. F5 BIG-IP LTM, etc. are all products of F5 Company in the United States. LTM is a local traffic manager; APM is a solution that provides secure unified access to business-critical applications and networks. The following products and versions are affected: BIG-IP LTM version 12.0.0 to version 12.1.2, version 11.6.0 to version 11.6.12, version 11.4.1 to version 11.5.42, version 11.2.1; BIG-IP Analytics 12.0.0 to 12.1.2, 11.6.0 to 11.6.12, 11.4.1 to 11.5.42, 11.2.1; BIG-IP APM 12.0.0 to 12.1.2, 11.6 .0 to 11.6.12, 11.4.1 to 11.5.42, 11.2.1; BIG-IP ASM 12.0.0 to 12.1.2, 11.6.0 to 11.6.12, 11.4. 1 to 11.5.42, 11.2.1; BIG-IP Link Controller 12.0.0 to 12.1.2, 11.6.0 to 11.6.12, 11.4.1 to 11.5.42, 11.2. 1 version; BIG-IP AAM version 12.0.0 to 12.1.2, 11.6.0 to 11.6.12, 11.4.1 to 11.5.42; BIG-IP AFM version 12.0.0 to 12.1.2 , version 11.6.0 to version 11.6.12, version 11.4.1 to version 11.5.42; BIG-IP PEM version 12.0.0 to version 12.1.2, version 11.6.0 to version 11.6.12, version 11.4.1 to Version 11.5.42; BIG-IP DNS versions 12.0.0 through 12.1.2; BIG-IP Edge Gateway 11.2

Trust: 1.98

sources: NVD: CVE-2017-6162 // JVNDB: JVNDB-2017-009799 // BID: 101635 // VULHUB: VHN-114365

AFFECTED PRODUCTS

vendor:f5model:big-ip local traffic managerscope:eqversion:12.1.1

Trust: 1.6

vendor:f5model:big-ip local traffic managerscope:eqversion:11.6.0

Trust: 1.6

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.2.1

Trust: 1.6

vendor:f5model:big-ip local traffic managerscope:eqversion:11.6.1

Trust: 1.6

vendor:f5model:big-ip local traffic managerscope:eqversion:12.1.0

Trust: 1.6

vendor:f5model:big-ip link controllerscope:eqversion:11.2.1

Trust: 1.3

vendor:f5model:big-ip link controllerscope:eqversion:11.6.1

Trust: 1.3

vendor:f5model:big-ip policy enforcement managerscope:eqversion:12.1.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:lteversion:11.5.4

Trust: 1.0

vendor:f5model:big-ip link controllerscope:gteversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.6.1

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:12.0.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:12.1.1

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:gteversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip websafescope:eqversion:1.0.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.6.1

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:12.0.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:lteversion:11.5.4

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:gteversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:eqversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:12.1.1

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:eqversion:12.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:lteversion:11.5.4

Trust: 1.0

vendor:f5model:big-ip application acceleration managerscope:lteversion:11.5.4

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:gteversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:12.1.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:12.1.1

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.2.1

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:11.6.1

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:12.0.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:eqversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:11.6.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:11.6.1

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:12.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:12.0.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:eqversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:gteversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip advanced firewall managerscope:gteversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:eqversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:12.1.1

Trust: 1.0

vendor:f5model:big-ip local traffic managerscope:lteversion:11.5.4

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:12.1.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:gteversion:11.5.0

Trust: 1.0

vendor:f5model:big-ip link controllerscope:eqversion:12.0.0

Trust: 1.0

vendor:f5model:big-ip application security managerscope:lteversion:11.5.4

Trust: 1.0

vendor:f5model:big-ip access policy managerscope:lteversion:11.5.4

Trust: 1.0

vendor:f5model:big-ip policy enforcement managerscope:eqversion:11.6.0

Trust: 1.0

vendor:f5model:big-ip access policy managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip advanced firewall managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip application acceleration managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip application security managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip link controllerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip policy enforcement managerscope: - version: -

Trust: 0.8

vendor:f5model:big-ip websafescope: - version: -

Trust: 0.8

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.4

Trust: 0.6

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.3

Trust: 0.6

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.5.1

Trust: 0.6

vendor:f5model:big-ip local traffic managerscope:eqversion:11.5.2

Trust: 0.6

vendor:f5model:big-ip application acceleration managerscope:eqversion:11.5.0

Trust: 0.6

vendor:f5model:big-ip websafescope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip websafescope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip websafescope:eqversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip websafescope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip webacceleratorscope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip psmscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip pemscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip ltmscope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:11.6

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip link controllerscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip gtmscope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip edge gatewayscope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip dnsscope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip asmscope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip apmscope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:11.2.1

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip analyticsscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip afmscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:12.0

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:11.6.1

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:11.6.0

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:11.5.4

Trust: 0.3

vendor:f5model:big-ip aamscope:eqversion:11.4.1

Trust: 0.3

vendor:f5model:big-ip websafe hf1scope:neversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip websafescope:neversion:11.6.2

Trust: 0.3

vendor:f5model:big-ip pem hf1scope:neversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip pemscope:neversion:11.6.2

Trust: 0.3

vendor:f5model:big-ip pemscope:neversion:11.5.5

Trust: 0.3

vendor:f5model:big-ip ltm hf1scope:neversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip ltmscope:neversion:11.6.2

Trust: 0.3

vendor:f5model:big-ip ltmscope:neversion:11.5.5

Trust: 0.3

vendor:f5model:big-ip link controller hf1scope:neversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip link controllerscope:neversion:11.6.2

Trust: 0.3

vendor:f5model:big-ip link controllerscope:neversion:11.5.5

Trust: 0.3

vendor:f5model:big-ip gtmscope:neversion:11.6.2

Trust: 0.3

vendor:f5model:big-ip gtmscope:neversion:11.5.5

Trust: 0.3

vendor:f5model:big-ip dns hf1scope:neversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip asm hf1scope:neversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip asmscope:neversion:11.6.2

Trust: 0.3

vendor:f5model:big-ip asmscope:neversion:11.5.5

Trust: 0.3

vendor:f5model:big-ip apm hf1scope:neversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip apmscope:neversion:11.6.2

Trust: 0.3

vendor:f5model:big-ip apmscope:neversion:11.5.5

Trust: 0.3

vendor:f5model:big-ip analytics hf1scope:neversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip analyticsscope:neversion:11.6.2

Trust: 0.3

vendor:f5model:big-ip analyticsscope:neversion:11.5.5

Trust: 0.3

vendor:f5model:big-ip afm hf1scope:neversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip afmscope:neversion:11.6.2

Trust: 0.3

vendor:f5model:big-ip afmscope:neversion:11.5.5

Trust: 0.3

vendor:f5model:big-ip aam hf1scope:neversion:12.1.2

Trust: 0.3

vendor:f5model:big-ip aamscope:neversion:11.6.2

Trust: 0.3

vendor:f5model:big-ip aamscope:neversion:11.5.5

Trust: 0.3

sources: BID: 101635 // JVNDB: JVNDB-2017-009799 // CNNVD: CNNVD-201710-1358 // NVD: CVE-2017-6162

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-6162
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-6162
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201710-1358
value: MEDIUM

Trust: 0.6

VULHUB: VHN-114365
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-6162
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-114365
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-6162
baseSeverity: MEDIUM
baseScore: 5.9
vectorString: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.2
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-114365 // JVNDB: JVNDB-2017-009799 // CNNVD: CNNVD-201710-1358 // NVD: CVE-2017-6162

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.9

sources: VULHUB: VHN-114365 // JVNDB: JVNDB-2017-009799 // NVD: CVE-2017-6162

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201710-1358

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-201710-1358

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-009799

PATCH

title:K13421245url:https://support.f5.com/csp/article/K13421245

Trust: 0.8

title:Multiple F5 product Traffic Management Microkernel Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=76066

Trust: 0.6

sources: JVNDB: JVNDB-2017-009799 // CNNVD: CNNVD-201710-1358

EXTERNAL IDS

db:NVDid:CVE-2017-6162

Trust: 2.8

db:SECTRACKid:1039673

Trust: 1.7

db:BIDid:101635

Trust: 1.4

db:JVNDBid:JVNDB-2017-009799

Trust: 0.8

db:CNNVDid:CNNVD-201710-1358

Trust: 0.7

db:VULHUBid:VHN-114365

Trust: 0.1

sources: VULHUB: VHN-114365 // BID: 101635 // JVNDB: JVNDB-2017-009799 // CNNVD: CNNVD-201710-1358 // NVD: CVE-2017-6162

REFERENCES

url:https://support.f5.com/csp/article/k13421245

Trust: 2.0

url:http://www.securitytracker.com/id/1039673

Trust: 1.7

url:http://www.securityfocus.com/bid/101635

Trust: 1.1

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-6162

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-6162

Trust: 0.8

url:http://www.f5.com/products/big-ip/

Trust: 0.3

sources: VULHUB: VHN-114365 // BID: 101635 // JVNDB: JVNDB-2017-009799 // CNNVD: CNNVD-201710-1358 // NVD: CVE-2017-6162

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 101635

SOURCES

db:VULHUBid:VHN-114365
db:BIDid:101635
db:JVNDBid:JVNDB-2017-009799
db:CNNVDid:CNNVD-201710-1358
db:NVDid:CVE-2017-6162

LAST UPDATE DATE

2024-11-23T22:00:50.181000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-114365date:2017-11-16T00:00:00
db:BIDid:101635date:2017-12-19T22:00:00
db:JVNDBid:JVNDB-2017-009799date:2017-11-22T00:00:00
db:CNNVDid:CNNVD-201710-1358date:2017-11-02T00:00:00
db:NVDid:CVE-2017-6162date:2024-11-21T03:29:10.440

SOURCES RELEASE DATE

db:VULHUBid:VHN-114365date:2017-10-27T00:00:00
db:BIDid:101635date:2017-10-26T00:00:00
db:JVNDBid:JVNDB-2017-009799date:2017-11-22T00:00:00
db:CNNVDid:CNNVD-201710-1358date:2017-10-27T00:00:00
db:NVDid:CVE-2017-6162date:2017-10-27T14:29:00.450