Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-6137


In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, WebAccelerator, and WebSafe 11.6.1 HF1, 12.0.0 HF3, 12.0.0 HF4, and 12.1.0 through 12.1.2, undisclosed traffic patterns received while software SYN cookie protection is engaged may cause a disruption of service to the Traffic Management Microkernel (TMM) on specific platforms and configurations.


Published

2017-05-09T15:29:00.407

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 5.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application f5 big-ip_local_traffic_manager 11.6.1 Yes
Application f5 big-ip_local_traffic_manager 12.0.0 Yes
Application f5 big-ip_local_traffic_manager 12.1.0 Yes
Application f5 big-ip_local_traffic_manager 12.1.1 Yes
Application f5 big-ip_local_traffic_manager 12.1.2 Yes
Application f5 big-ip_application_acceleration_manager 11.6.1 Yes
Application f5 big-ip_application_acceleration_manager 12.0.0 Yes
Application f5 big-ip_application_acceleration_manager 12.1.0 Yes
Application f5 big-ip_application_acceleration_manager 12.1.1 Yes
Application f5 big-ip_application_acceleration_manager 12.1.2 Yes
Application f5 big-ip_advanced_firewall_manager 11.6.1 Yes
Application f5 big-ip_advanced_firewall_manager 12.0.0 Yes
Application f5 big-ip_advanced_firewall_manager 12.1.0 Yes
Application f5 big-ip_advanced_firewall_manager 12.1.1 Yes
Application f5 big-ip_advanced_firewall_manager 12.1.2 Yes
Application f5 big-ip_analytics 11.6.1 Yes
Application f5 big-ip_analytics 12.0.0 Yes
Application f5 big-ip_analytics 12.1.0 Yes
Application f5 big-ip_analytics 12.1.1 Yes
Application f5 big-ip_analytics 12.1.2 Yes
Application f5 big-ip_access_policy_manager 11.6.1 Yes
Application f5 big-ip_access_policy_manager 12.0.0 Yes
Application f5 big-ip_access_policy_manager 12.1.0 Yes
Application f5 big-ip_access_policy_manager 12.1.1 Yes
Application f5 big-ip_access_policy_manager 12.1.2 Yes
Application f5 big-ip_application_security_manager 11.6.1 Yes
Application f5 big-ip_application_security_manager 12.0.0 Yes
Application f5 big-ip_application_security_manager 12.1.0 Yes
Application f5 big-ip_application_security_manager 12.1.1 Yes
Application f5 big-ip_application_security_manager 12.1.2 Yes
Application f5 big-ip_domain_name_system 12.0.0 Yes
Application f5 big-ip_domain_name_system 12.1.0 Yes
Application f5 big-ip_domain_name_system 12.1.1 Yes
Application f5 big-ip_domain_name_system 12.1.2 Yes
Application f5 big-ip_global_traffic_manager 11.6.1 Yes
Application f5 big-ip_link_controller 11.6.1 Yes
Application f5 big-ip_link_controller 12.0.0 Yes
Application f5 big-ip_link_controller 12.1.0 Yes
Application f5 big-ip_link_controller 12.1.1 Yes
Application f5 big-ip_link_controller 12.1.2 Yes
Application f5 big-ip_policy_enforcement_manager 11.6.1 Yes
Application f5 big-ip_policy_enforcement_manager 12.0.0 Yes
Application f5 big-ip_policy_enforcement_manager 12.1.0 Yes
Application f5 big-ip_policy_enforcement_manager 12.1.1 Yes
Application f5 big-ip_policy_enforcement_manager 12.1.2 Yes
Application f5 big-ip_websafe 11.6.1 Yes
Application f5 big-ip_websafe 12.0.0 Yes
Application f5 big-ip_websafe 12.1.0 Yes
Application f5 big-ip_websafe 12.1.1 Yes
Application f5 big-ip_websafe 12.1.2 Yes

References