CVE-2016-6876
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
The RESOLV::lookup iRule command in F5 BIG-IP LTM, APM, ASM, and Link Controller 10.2.1 through 10.2.4, 11.2.1, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.0.0 before HF3; BIG-IP AAM, AFM, and PEM 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.0.0 before HF3; BIG-IP Analytics 11.2.1, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.0.0 before HF3; BIG-IP DNS 12.0.0 before HF3; BIG-IP Edge Gateway, WebAccelerator, and WOM 10.2.1 through 10.2.4 and 11.2.1; BIG-IP GTM 10.2.1 through 10.2.4, 11.2.1, 11.4.x, 11.5.x before 11.5.4 HF2, and 11.6.x before 11.6.1; and BIG-IP PSM 10.2.1 through 10.2.4 and 11.4.0 through 11.4.1 allows remote DNS servers to cause a denial of service (CPU consumption or Traffic Management Microkernel crash) via a crafted PTR response.
Affected (128)
Products: F5: Big Ip Local Traffic Manager, Big Ip Webaccelerator, Big Ip Application Acceleration Manager, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Advanced Firewall Manager, Big Ip Protocol Security Module, Big Ip Wan Optimization Manager, Big Ip Application Security Manager, Big Ip Policy Enforcement Manager, Big Ip Domain Name System, Big Ip Analytics, Big Ip Edge Gateway, Big Ip Access Policy Manager
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.2.1 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.2.1 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.2.1 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.2.1 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4.0 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.2.1 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.2.1 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.2.1 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.4.0 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.0.0 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.2.1 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.2.1 |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.2.1 |
Related CWEs
References (4)
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.