In some circumstances, the Traffic Management Microkernel (TMM) does not properly handle certain malformed Websockets requests/responses, which allows remote attackers to cause a denial-of-service (DoS) or possible remote code execution on the F5 BIG-IP system running versions 13.0.0 - 13.1.0.3 or 12.1.0 - 12.1.3.1.
2018-03-22T18:29:00.637
2024-11-21T04:08:56.280
Modified
CVSSv3.0: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | f5 | big-ip_access_policy_manager | < 12.1.3.2 | Yes |
| Application | f5 | big-ip_access_policy_manager | < 13.1.0.4 | Yes |
| Application | f5 | big-ip_advanced_firewall_manager | ≤ 12.1.3.2 | Yes |
| Application | f5 | big-ip_advanced_firewall_manager | < 13.1.0.4 | Yes |
| Application | f5 | big-ip_analytics | < 12.1.3.2 | Yes |
| Application | f5 | big-ip_analytics | < 13.1.0.4 | Yes |
| Application | f5 | big-ip_application_acceleration_manager | < 12.1.3.2 | Yes |
| Application | f5 | big-ip_application_acceleration_manager | < 13.1.0.4 | Yes |
| Application | f5 | big-ip_application_security_manager | < 12.1.3.2 | Yes |
| Application | f5 | big-ip_application_security_manager | < 13.1.0.4 | Yes |
| Application | f5 | big-ip_domain_name_system | < 12.1.3.2 | Yes |
| Application | f5 | big-ip_domain_name_system | ≤ 13.1.0.4 | Yes |
| Application | f5 | big-ip_edge_gateway | < 12.1.3.2 | Yes |
| Application | f5 | big-ip_edge_gateway | < 13.1.0.4 | Yes |
| Application | f5 | big-ip_global_traffic_manager | < 12.1.3.2 | Yes |
| Application | f5 | big-ip_global_traffic_manager | < 13.1.0.4 | Yes |
| Application | f5 | big-ip_link_controller | < 12.1.3.2 | Yes |
| Application | f5 | big-ip_link_controller | < 13.1.0.4 | Yes |
| Application | f5 | big-ip_local_traffic_manager | < 12.1.3.2 | Yes |
| Application | f5 | big-ip_local_traffic_manager | < 13.1.0.4 | Yes |
| Application | f5 | big-ip_policy_enforcement_manager | < 12.1.3.2 | Yes |
| Application | f5 | big-ip_policy_enforcement_manager | < 13.1.0.4 | Yes |
| Application | f5 | big-ip_webaccelerator | < 12.1.3.2 | Yes |
| Application | f5 | big-ip_webaccelerator | < 13.1.0.4 | Yes |
| Application | f5 | big-ip_websafe | 1.0.0 | Yes |