CVE-2017-6156
6.4
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H
Exploitability: 1.6 / Impact: 4.7
Source: NVD
Description
When the F5 BIG-IP 12.1.0-12.1.1, 11.6.0-11.6.1, 11.5.1-11.5.5, or 11.2.1 system is configured with a wildcard IPSec tunnel endpoint, it may allow a remote attacker to disrupt or impersonate the tunnels that have completed phase 1 IPSec negotiations. The attacker must possess the necessary credentials to negotiate the phase 1 of the IPSec exchange to exploit this vulnerability; in many environment this limits the attack surface to other endpoints under the same administration.
Affected (52)
Products: F5: Big Ip Local Traffic Manager, Big Ip Application Acceleration Manager, Big Ip Advanced Firewall Manager, Big Ip Analytics, Big Ip Access Policy Manager, Big Ip Application Security Manager, Big Ip Edge Gateway, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Policy Enforcement Manager, Big Ip Webaccelerator, Big Ip Websafe, Big Ip Domain Name System
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.5.5 |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.